He found a way to Hijack Private Google Docs Screenshots with a clever hack - Google paid him $4000

The Backend Engineering Show with Hussein Nasser - A podcast by Hussein Nasser

Categories:

A vulnerability in Google Feedback component in postMessage allowed this security researcher to find a way to hijack private screenshots   https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/ https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage