Google Maps XSS Bug – Bounty Doubled After the Original Fix had Failed

Google repaired the vulnerability with Google Maps that was reported through Google Vulnerability Reward Program (VRP) and in return, the researchers are paid with monetary rewards.

The XSS vulnerability with Google Maps discovered by Zohar Shachar, Head of Application Security at Wix, and reported to Google through their bug bounty program.

XSS with Google Maps

He likewise offered the steps to reproduce the issue. The bug was reported to Google and they paid 5000$ bounty.

The vulnerability lives in Google Maps that are utilized for creating your map. Once you have the maps created you can export them in various formats such as CSV, XLSX, KML, or GPX.

According to Shachar, “by including]] > at the beginning of your payload (I.e. as the start of the map name), you can get away from the CDATA and include approximate XML content (which will be rendered as XML)– leading instantly to XSS.”

Shachar exported the map in KML format that was utilized to display geographic data in an Earth internet browser such as Google Earth.

The map name was found to be present in the CDATA tag “which means our code will not be rendered by the web browser.”

Bypassing the Fix

Within two hours, Google acknowledged the problem and resumed the case, and updated the bug.

To repair the closing of the CDATA tag Google added another CDATA tag, Shachar reported the issue once again to Google.

” I was genuinely surprised the bypass was so simple. I reported it so quickly (actually 10 minutes in between inspecting my mail box and reporting a bypass), that right after sending this mail I started questioning myself.”

The very first XSS concern was reported to Google on April 23 & & fixed on June 7, the bypass to the patch reported on the very same day and the concern fixed, the second payment provided on June 18. For each vulnerability report Shachar $5,000, so the overall benefit is $10,000.

” Ever considering that this Google-maps repair bypass event I began to always re-validate fixes, even for simple things, and it has actually been paying off. I full-heartedly motivate you to do the exact same,” Shachar stated.

You can follow us on Linkedin, Twitter, Facebook for day-to-day Cybersecurity updates

Also Read:

Lazarus APT Hackers Attack Japanese Organization Using Remote SMB Tool “SMBMAP” After Network Intrusion

PoetRAT– New Python RAT Attacking Government and Energy Sector Via Weaponized Word Documents