How Google Is Stopping Phishing Attacks From Unverified Apps

How Google Is Stopping Phishing Attacks From Unverified Apps

Google is stepping up its effort to block phishing attempts that use app permissions to gain access to users’ Gmail accounts. These phishing attacks invite users to grant an app permission to manage their Google account — which a lot of safe apps do, too — and then exploit those permissions to take over an account or send spam.

Photo: AP

To stop these kinds of attacks, Google is adding a screen to the permissions process that will warn users if the app is new or unverified — signs that it might be linked to a phishing attempt.

“The ‘unverified app’ screen precedes the permissions consent screen for the app and lets potential users know that the app has yet to be verified. This will help reduce the risk of user data being phished by bad actors,” Google’s Naveen Agarwal and Wesley Chun wrote in a blog post announcing the change.

The warning looks a little bit like Chrome’s warning when a site’s HTTPS encryption isn’t trusted. It requires users to click into advanced settings before they can commit to granting permissions to the app. Here’s what the warning will look like:

How Google Is Stopping Phishing Attacks From Unverified Apps
Courtesy of Google

Courtesy of Google

Google recently started requiring new apps to go through a verification process to assess possible risks before being approved. In addition to the new warning system, Google will require some existing apps to undergo the verification process.

The warnings and reviews are intended to shore up an area of vulnerability for Gmail users, who may not be aware of the security risks that come with granting permissions to untrusted apps. These kinds of OAuth exploits are on the rise, so it’s good to see Google working to prevent them.


The Cheapest NBN 50 Plans

It’s the most popular NBN speed in Australia for a reason. Here are the cheapest plans available.

At Gizmodo, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.