
Google said on Thursday it fixed a flaw in its site that could allow outsiders to launch phishing attacks based on Google’s familiar interface, and is working on a second fix for another similar vulnerability. The flaw, which was discovered and posted to Symantec’s Bugtraq security site on Tuesday, demonstrated the ability of hackers using JavaScript to modify and enter their own content within Google’s site in order to obtain personal information, including credit card numbers.