Security Expert Brett Buerhaus has discovered a critical flaw on admin.google.com. The Google Apps administrator console is affected by a critical cross-site scripting (XSS) vulnerability that could be exploited by attackers to force a Google Apps admins to execute request on the https://admin.com/ domain. Google promptly resolved the problem and fixed the flaw within 17 days. The vulnerability was discovered by a security engineer who received $5,000 as a reward under its bug bounty program.”]
Source: https://securityaffairs.co/wordpress/32615/hacking/google-account-hijacking-via-xss.html