He found a way to Hijack Private Google Docs Screenshots with a clever hack - Google paid him $4000
The Backend Engineering Show with Hussein Nasser - A podcast by Hussein Nasser
Categories:
A vulnerability in Google Feedback component in postMessage allowed this security researcher to find a way to hijack private screenshots https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/ https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage