Product

Google Fixes Search De-Indexing Flaw That Allowed Unauthorized Content Removal

Researchers uncovered a vulnerability in Google's web indexing system that attackers exploited to suppress search results, prompting the search giant to deploy a patch.

·2 min read
Google Patches Vulnerability That Let Anyone Hide Search Results
Google Patches Vulnerability That Let Anyone Hide Search Results

Independent journalist Jack Poulson and the nonprofit Freedom of the Press Foundation disclosed on Wednesday that a component of Google's indexing infrastructure had been weaponized to erase web pages from search results. The vulnerability exposed how Google's mechanisms for cataloging web content could be turned against the system to conceal publicly available information.

How the Refreshed Outdated Content exploit works

Poulson and Ahmed Zidan, deputy director of audience at Freedom of the Press Foundation, identified that a piece published on the foundation's site had been stripped from Google's index without authorization. The article in question discussed alleged efforts to suppress details about tech CEO Maury Blackman's 2021 arrest on suspicion of domestic violence, a charge that resulted in neither conviction nor prosecution.

The attacker leveraged Google's Refresh Outdated Content tool, which the company describes as a mechanism to remove listings for pages that have ceased to exist or that have "deleted important (sensitive or critical) content."

The Refresh Outdated Content tool operates under the constraint that it is meant for people who do not control the webpage in question; those with ownership must employ a separate mechanism accessible through Google Search Console.

According to Freedom of the Press Foundation, the vulnerability stemmed from the tool's susceptibility to manipulation through submission of slightly modified URLs—such as variations in letter casing—that directed to 404 error pages. Google's system failed to recognize that uppercase and lowercase versions were identical, resulting in the legitimate page being delisted alongside the error variants.

In the Freedom of the Press Foundation scenario, an adversary submitted the same URLs repeatedly with different capitalizations. Each time the article reappeared in search results, the attacker would resubmit the manipulated URLs to trigger another de-indexing cycle.

Google rolled out a fix

After Freedom of the Press Foundation notified Google on June 27, the company implemented a remedy for the vulnerability.

According to Freedom of the Press Foundation's correspondence with Google, the vulnerability touched "a tiny fraction of websites." Google has not disclosed the total number of additional sites that may have been de-indexed through this method.

Confirming that we've rolled out a fix to prevent this type of abuse of the 'Refresh Outdated Content Tool,'

anonymous Google spokesperson

The Google representative declined to elaborate further on the matter.