Google Downplays Undocumented Chrome API Exploited by Malware to Extend Account Theft: Report

Researchers have found malware using a novel technique to prolong access to stolen Google accounts. An undocumented Chrome API, known as the “MultiLogin” API endpoint, is being misused to revive expired Google authentication cookies, allowing hackers continued access. Google is underscoring the severity of this undocumented API vulnerability while security experts call for more transparency and urge users to regularly update Chrome.

