According to foreign media reports, Google + recently revealed a security vulnerability that allows users to retrieve instant messaging contacts and conversation information from others on a shared PC in some cases, make real-time eavesdropping possible. Google has admitted that Google + has this vulnerability and said it is working hard to fix it.
According to reports, Google Talk integrates other instant messaging services in a way similar to GMail, which requires uninterrupted contact with Google's Instant Messaging Server. A vulnerability exists at this stage. According to technical personnel, this vulnerability can be caused in the following situations: User A simultaneously opens GMail and Google +, and then the network connection is interrupted for A short time, so that the Google Talk process and Google + are temporarily out of sync. User B borrowed the computer, logged out of user A's GMail account, and logged on to user A's GMail. In this case, Google Talk in user A's Google + will automatically log out and log in with user B's account.
In this case, when user B returns the computer, user A will find that the Google Talk window of user B appears on its Google + Page. Any real-time information sent to user B is displayed on user A's screen. It is understood that although the vulnerability has a low probability, many users have reported it was affected. This phenomenon also occurs between multiple GMail accounts of the same user.
A Google spokesman admitted that the vulnerability exists and said Google is working on a solution. The spokesman also suggested that users log out of Google accounts when sharing computers.