STEWIE NOT DOG, HUNT SOME BUGS MY BOY!!!!     Google AdWords , is Google's advertising system in which advertisers bid on certain keywords in their searchable ads. Since advertisers have to pay for these clicks, Google makes money from search.         ISSUE : A user with read only access to the adwords account was able to link Youtube channels to the adwords account.       Reported: 5th April       Steps to reproduce:   1. Go to https://adwords.google.com create a test adwords account.   From settings, Account access add another userA with Read-only access   (Here's the access right is allocated as read only users)   Now   3. Go to user A mail account and accept the invitation to join the adwords account.   4. from user A adwords account go to settings then Linked accounts and then youtube, with below description:     YouTube channels   Link a YouTube channel to your AdWords account to gain greater insights about your customers.     5. Add a youtube channel and...
  Facebook WhiteHat: Able to access group plan even after leaving the group.   Product/URL :    https://www.facebook.com/messages/t/[group_messagesID]   Description and Impact   Facebook messages has an option to create group, where a user can add multiple friends to chat, plan share pictures together.     Whenever a user is not a part of the group, he is not allowed to see the updated information of the group.     However one can still access the group plan even when not in a group.     Peter, is it?       Reproduction Instructions/Proof of Concept   We have two test accounts, (test A) and (test B)     1. Test A Creates a new Group, Test Group, add members.(test B, test C )   2. Test A creates a plan in group, with date, venue and plan name.   3. There is some argument between Test A and Test B, and Test B leaves the group.   4. Test A and Test C decides to change the plan venue as Test B was already aware of the all plan details.   5. Test A changes the plan venue and date, howev...