Simple Google Bug Allows Hackers to Spoof Search Results
A newly documented bug in Google Search allows anyone to easily manipulate Knowledge Graph cards to spread misinformation through deceptive links.
A security researcher discovers a simple bug in Google Search that allows anyone to easily manipulate search results. By splicing together URL values from Google's Knowledge Graph cards, a malicious user changes the quick facts that appear on the right side of the screen. This exploit makes it possible to alter answers for basic questions, such as changing the capital of Britain from London to Mars.
The manipulated links do not break HTTPS security, meaning they look completely legitimate to the average internet user. Bad actors easily share these deceptive links through emails, Twitter, or Facebook without raising any suspicion. This creates a dangerous avenue for spreading false information, as recipients naturally trust the results they see on Google.
Expert Wietze Beukema warns that this flaw fuels real-world misinformation and propaganda campaigns. The bug allows attackers to promote dangerous conspiracy theories, such as misidentifying the perpetrators of 9/11 or misstating former President Barack Obama's birthplace. Beukema reports that he initially alerted Google to this issue in December 2017, but the company closes the report without taking any action to fix the vulnerability.