Following a revelation of a major security flaw in Google Calendar, Gmail users are being urged to be vigilant against spam calendar invitations containing malicious links that can let hackers take over their account.
The vulnerability allows a hacker to take advantage of a default setting that automatically adds invitations to a user’s Calendar they are sent via email. These spam invites pop up as a notification through the Google Calendar app, which if the user clicks takes them to an official-looking site to capture login credential and other sensitive information such as how to access the area where the event is to take place.
Google said it is “working diligently” to fix the flaw and wrote in an update to its Calendar Help page: “We’re aware of the spam occurring in Calendar and are working diligently to resolve this issue.”
“We’ll post updates to this thread as they become available…Thank you for your patience,” it added.
Recommended
- Audio-Visual Communications Specialist to Open Edinburgh Office
- arbnco Project to Explore How Tech Can Improve Council Housing Conditions
- France to Block Facebook’s Libra Cryptocurrency
Google advises users to report any inappropriate or suspicious calendar invites or event as spam. This action will remove all events from that organiser from Calendar.
The phoney invites were first flagged by security researchers at Black Hills Information Security (BHIS) in 2017, but Google is only now taking action to fix the problem.
In a blog detailing the vulnerability, the researchers described how security controls meant to prevent such attacks could be easily bypassed. They discovered that an email was not necessary to create an event in someone’s calendar as it can be done manually through Google Calendar UI.
“When you create an event and add guests, Google will ask you whether you would like to send invitations to the guests after saving it. Simply selecting “Don’t Send” will save the event to the guest’s calendar if it is a Google account and not send them an email,” they explained.
BHIS researchers said this feature could be particularly useful to hackers in phising users of a G Suite environment. Most users, they noted, are now more cautious of phishing links in email, therefore, receiving an official notification via Google Calendar is less likely to raise a user’s suspicions.
“Possibly the most interesting element of the calendar is that it can create a sense of urgency simply by alerting a user to something. Perhaps the user completely ‘forgot’ they had a meeting scheduled,” the blog continued.
Cyber security awareness advocate, Javvad Malik told Forbes, that it would be wrong to think of this vulnerability as just being spam.
“Beyond phishing, this attack opens up the doors for a whole host of social engineering attacks,” he said.






