
<p>Google has fixed a bug in its Gmail account retrieval and password reset process that could have allowed an attacker to fool a user into handing over their details.</p><p>The bug, discovered by white-hat hacker Oren Hafif, has since been fixed and was confirmed as a 'high impact' vulnerability by Googler Sebastian Roschke on Google +.</p><p>While we won't go into the technical details of how Hafif pulled off the hack, you can see a quick overview of the spear-phishing attack in the video below.</p><p>One of the worrying things is that as part of the process, the user is actually directed to a genuine HTTPS Google.com webpage at one point.</p><p><a href="http://thenextweb.com/google/2013/11/22/google-patches-serious-gmail-account-vulnerability-password-reset-system/">Keep reading...</a></p><p>Read also:</p><p><a href="http://www.theregister.co.uk/2013/11/22/researcher_earns_payday_for_fixing_high_impact_gmail_password_flaw/">'High impact' Gmail password security hole blew accounts wide open</a> (Register)</p><p><a href="http://grahamcluley.com/2013/11/security-hole-gmail-password-recovery-system/">Serious security hole in Gmail password reset system found by security researcher</a> (Graham Cluley Security News)</p><p><a href="http://threatpost.com/details-on-patched-google-account-recovery-bug-disclosed">Details on Patched Google Account Recovery Bug Disclosed</a> (Threatpost)</p><p>Explore: <a href="http://news.google.com/news/more?ncl=dMayLU0n6L_rcfM7LCg40Jh9Fn66M&ned=us">7 additional articles.</a></p>