Bug on Gmail for Android allows sending Spoofing Emails

A security researcher discovered an interesting vulnerability in the Gmail app for , which allows anyone to send e-mail that looks like it was sent by someone else. Gmail spoof alert

This behavior is used by Phishers to deceive their victims. It is called E-mail Spoofing and usually an email header is forged to appear to be from someone else.

Independent security researcher Yan Zhu discovered the bug in the official Gmail app for Android devices.

The bug allowed her to hide her real address and change her display name from account. So the receiver cannot know the real sender.

How to send Spoofing via Gmail for Android?

To prove her point, Zhu sent an email to someone, changing her name on the screen by adding extra quotes "" security@google.com ". You can see below the screenshot posted by Zhu on Twitter.

"Extra quotes [in the displayed name] cause a parsing error in the Gmail application, which makes the actual e-mail invisible," Zhu told

Google: "Bug is not a security vulnerability"

Zhu reported the flaw to Google's security team in late October, but the team dismissed her report, saying the bug was not a security vulnerability.

"Thanks for your note, we do not consider the bug a security vulnerability," a member of Google's security team told Zhu.

"A Gmail bug in Android that allows you to send emails with a fake address is not a security issue for Google. ¯ \ _ (ツ) _ / ¯ ”. wrote Zhu.

And the picture published by the researcher:

Yan Zhu

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).