Two researchers have shown how a modded version of the Firesheep Wi-Fi sniffing tool can be used to access most of a victim’s Google Web History, a record of everything an individual has searched for. The core weakness lies with what is called a Session ID (SID) cookie, used to identify a user to each service they access while logged in to one of Google’s services. The most direct method is to set up a rogue access point and then use an iFrame to direct the user to a Google service (such as Alerts) that doesn’t use an encrypted channel.”]
Source: https://www.csoonline.com/article/2129574/google-web-history-vulnerable-to-new-firesheep-hack.html

