Is It Safe to Share Your Files? An Empirical Security Analysis of Google Workspace
Liuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong Bai
Abstract
The increasing demand for remote work and virtual interactions has heightened the usage of business collaboration platforms (BCPs), with Google Workspace as a prominent example. These platforms enhance team collaboration by integrating Google Docs, Slides, Calendar, and feature-rich third-party applications (add-ons). However, such integration of multiple users and entities has inadvertently introduced new and complex attack surfaces, elevating security and privacy risks in resource management to unprecedented levels. In this study, we conduct a systematic study on the effectiveness of the cross-entity resource management in Google Workspace, the most popular BCP. Our study unveils the access control enforcement in real-world BCPs for the first time. Based on this, we formulate the attack surfaces inherent in BCPs and conduct a comprehensive assessment, pinpointing three vulnerability types leading to distinct attacks. An analysis of 4,732 marketplace add-ons reveals that approximately 70% are potentially vulnerable to these attacks. We propose robust countermeasures to improve BCP security, urging immediate action and setting a foundation for future research.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6113511a-0281-4b21-9fff-a97e6eb9b07bCited by top-tier papers1
Ask how each one uses itBuilds on16
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 684 citations
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu et al.USENIX Security 2018 · 236 citations
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 119 citations
- Finding Clues for Your Secrets: Semantics-Driven, Learning-Based Privacy Discovery in Mobile AppsYuhong Nan, Zhemin Yang, Xiaofeng Wang, Yuan Zhang et al.NDSS 2018 · 79 citations
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 68 citations
Related papers
- Understanding DevOps Security of Google Workspace AppsLiuhuo Wan, Chuan Yan, Zicong Liu, Haoyu Wang et al.ICSE 2026
- Unveiling AI-Driven Web Applications: Insights into Characteristics, Functionality, and ComplianceLiuhuo Wan, Zicong Liu, Chuan Yan, Liujia Wan et al.FSE 2026
- Experimental Security Analysis of the App Model in Business Collaboration PlatformsYunang Chen, Yue Gao, Nick Ceccio, Rahul Chatterjee et al.USENIX Security 2022
- Security and Privacy Perceptions of Third-Party Application Access for Google AccountsDavid G. Balash, Xiaoyuan Wu, Miles Grant, Irwin Reyes et al.USENIX Security 2022
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu et al.CCS 2023 · 15 citations
