{"id":31883,"date":"2019-11-18T15:01:56","date_gmt":"2019-11-18T15:01:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/30694\/Google-Patches-Awesome-XSS-Vulnerability-In-Gmail-Dynamic-Email-Feature.html"},"modified":"2019-11-18T15:01:56","modified_gmt":"2019-11-18T15:01:56","slug":"google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/","title":{"rendered":"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2019\/11\/18\/d5a43df0-86c3-4dfe-8785-d44b2098ab4c\/thumbnail\/770x578\/29c87db2b453c9819cf31e9cd49ed795\/screenshot-2019-11-18-at-08-38-58.png\" class=\"ff-og-image-inserted\"><\/div>\n<p>Google has resolved an XSS vulnerability in Gmail described by the tech giant&#8217;s own team as &#8220;awesome.&#8221;<\/p>\n<p>On Monday, Micha\u0142 Bentkowski, Chief Security Researcher at <a href=\"https:\/\/securitum.pl\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Securitum<\/a>, disclosed the vulnerability through a responsible disclosure process after the bug had been resolved.&nbsp;<\/p>\n<p><a href=\"https:\/\/research.securitum.com\/xss-in-amp4email-dom-clobbering\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">In a blog post<\/a>, Bentkowski said the security flaw was present in AMP4Email, a feature in Gmail pushed out to general availability in July.&nbsp;<\/p>\n<p>AMP4Email, also known as <a href=\"https:\/\/gsuiteupdates.googleblog.com\/2019\/06\/dynamic-email-in-gmail-becoming-GA.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">dynamic email<\/a>, was implemented to make it easier for dynamic content to show up in emails, such as comment threads or event invitations.&nbsp;<\/p>\n<p>AMP4Email does have a validation system in place to prevent cross-site scripting (XSS) attacks from being used to abuse the feature. Certain tags and attributes are whitelisted, and should someone attempt to add another element or attribute that is not permitted, errors occur.<\/p>\n<p>However, the security researcher noticed that the id attribute is not disallowed in tags, leading to an investigation into whether or not AMP4Email could be subject to <a href=\"https:\/\/fastmail.blog\/2015\/12\/20\/sanitising-html-the-dom-clobbering-issue\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">DOM Clobbering<\/a>.&nbsp;<\/p>\n<p><strong>See also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/these-software-vulnerabilities-top-mitres-most-dangerous-list-in-2019\/\" target=\"_blank\" rel=\"noopener noreferrer\">These software vulnerabilities top MITRE&#8217;s most dangerous list<\/a><\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>Document Object Model (DOM) Clobbering has been caused by the gradual increase in complexity when it comes to digital messaging. Emails are rarely now only text-based, and while attempting to facilitate additional content, sanitization has become crucial &#8212; but, sometimes, issues in whitelisting can be exploited to deploy XSS attacks.&nbsp;<\/p>\n<p>&#8220;DOM Clobbering is a legacy feature of web browsers that just keeps causing trouble in many applications,&#8221; the researcher says. &#8220;When you create an element in HTML (for instance) and then you wish to reference it from JavaScript, you would usually use a function like document .getElementById(&#8216;username&#8217;) or document .querySelector(&#8216;#username&#8217;). The legacy way is to just access it via a property of global window object. So window.username is in this case exactly the same as document.getElementById(&#8216;username&#8217;).&#8221;<\/p>\n<p>In AMP4Email, some values for the id attribute are restricted. However, when in AMP_MODE, an error caused a 404 if the function tried to load JS files, causing an &#8216;undefined&#8217; portion in the resultant URL.&nbsp;<\/p>\n<p><strong>CNET:&nbsp;<\/strong><a href=\"https:\/\/www.cnet.com\/news\/most-americans-dont-think-its-possible-to-keep-their-data-private-report-says\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Most Americans don&#8217;t think it&#8217;s possible to keep their data private, report says<\/a><\/p>\n<p>&#8220;AMP tries to get a property of AMP_MODE to put it in the URL,&#8221; the researcher says. &#8220;Because of DOM Clobbering, the expected property is missing, hence undefined.&#8221;<\/p>\n<p>The code responsible for the undefined element checks to see if AMP_MODE.test and window.testLocation are truthy, but it was noticed that the URL could be controlled by writing a payload to overload window.testLocation.<\/p>\n<p>In a real-world scenario, however, a Content Security Policy (CSP) function in AMP stopped the code from fully executing.&nbsp;<\/p>\n<p><strong>TechRepublic:&nbsp;<\/strong><a href=\"https:\/\/www.techrepublic.com\/article\/cybersecurity-remains-the-top-concern-for-middle-market-companies\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Cybersecurity remains the top concern for middle market companies<\/a><\/p>\n<p>The vulnerability was reported via the Google Vulnerability Reward Program on 15 August 2019.&nbsp; A day later, Google&#8217;s team accepted the report, and by 10 September, the team said: &#8220;The bug is awesome, thanks for reporting!&#8221;&nbsp;<\/p>\n<p>The tech giant notified Bentkowski on 12 October that the bug had been resolved, leading to public disclosure.&nbsp;<\/p>\n<p>ZDNet has reached out to Google but has not heard back at the time of publication.&nbsp;<\/p>\n<h3>Previous and related coverage<\/h3>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/30694\/Google-Patches-Awesome-XSS-Vulnerability-In-Gmail-Dynamic-Email-Feature.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":31884,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8277],"class_list":["post-31883","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlineemailflawgoogle"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-11-18T15:01:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature\",\"datePublished\":\"2019-11-18T15:01:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/\"},\"wordCount\":571,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png\",\"keywords\":[\"headline,email,flaw,google\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/\",\"name\":\"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png\",\"datePublished\":\"2019-11-18T15:01:56+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,email,flaw,google\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineemailflawgoogle\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/","og_locale":"en_US","og_type":"article","og_title":"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-11-18T15:01:56+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature","datePublished":"2019-11-18T15:01:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/"},"wordCount":571,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png","keywords":["headline,email,flaw,google"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/","url":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/","name":"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png","datePublished":"2019-11-18T15:01:56+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature.png","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/google-patches-awesome-xss-vulnerability-in-gmail-dynamic-email-feature\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,email,flaw,google","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineemailflawgoogle\/"},{"@type":"ListItem","position":3,"name":"Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/31883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=31883"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/31883\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/31884"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=31883"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=31883"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=31883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}