Gmail bug exposes your mail account to spammers

The exploit takes advantage of the fact that Google puts your details into a <span class="highligh" style="color: #000; background-color:#d7ffa7;">Jspan>S file. As a result, if you're logged into Gmail and browsing the web, any rogue website can declare the function "google" and then parse all your contacts. The only way to safeguard yourself is to disable <span class="highligh" style="color: #000; background-color:#d7ffa7;">Jspan>avascript in your browser (or enabled it for trusted sites only) or simply climb into a hole and not browse while logged into Google services like Gmail, Blogger, Orkut, Reader, Calendar, etc.





