Overview
- Security researchers Brutecat and Nathan discovered two vulnerabilities in YouTube and Pixel Recorder APIs that exposed users' Gaia IDs and linked email addresses.
- The exploit allowed attackers to retrieve Gaia IDs from YouTube live chat features and convert them into email addresses using a loophole in the Pixel Recorder app.
- The vulnerability posed significant privacy risks, especially for anonymous users such as activists, whistleblowers, and content creators.
- Google patched the flaw on February 9, 2025, after the researchers disclosed it in September 2024, confirming no evidence of active exploitation during the exposure period.
- The researchers were awarded $10,633 for their findings, which highlighted broader concerns about Gaia ID leaks across multiple Google services.