Google’s Redirect Roulette: How a Tiny Parameter Became a Phisher’s Playground
A CWE-601 Open Redirect vulnerability on apis.google.com has been exploited in phishing attacks since September 2025. Attackers are redirecting unsuspecting users to malicious sites using the “__lu” parameter. Google, consider this a gentle nudge—or a not-so-gentle shove—to fix your open redirects!

Hot Take:
Google’s got a redirect problem, and it’s about as sneaky as a cat burglar with a cowbell. The “__lu” parameter on apis.google.com is like a mischievous toddler, causing chaos and mayhem through the art of redirection. Someone tell Google that open redirects are so 2020s!
Key Points:
- Open Redirect vulnerability found on apis.google.com using “__lu” parameter.
- Actively exploited in phishing attacks since September 2025.
- Allows attackers to craft URLs that appear to be from Google but redirect elsewhere.
- Severity rating: Medium due to confirmed exploitation in the wild.
- Google, please fix this before we end up in an alternate universe!
Already a member? Log in here
