
First discovered on a hacker website and reported by an anonymous researcher known as Maluc, the flaw makes it easy to create believable and large-scale phishing attacks.
John Herron, who runs NIST.org, reported the problem to US-CERT (U.S. Computer Emergency Readiness Team), which informed Google of the problem.
Google reported that it released a fix on Monday, but only a handful of those affected have used the workaround. Organisations that use either appliance are highly encouraged to contact Google if they have not yet heard from the company.
Click here to email Ericka Chickowski.