Posted by Jad Boutros on Jun 30
Hi Pathric,
We've taken a closer look and haven't been able to replicate the bug. The
PoC URL appears malformed and/or incomplete.
Feel free to contact us directly via security () google com if you'd like to
clarify. Also, don't forget that bugs that are privately reported under the
vulnerability reward program are eligible for a cash rewards! (
http://www.google.com/about/corporate/company/rewardprogram.html)
Source: Re: google plus vuln to XSS




