Privacy breach: apps can figure out the email address from my Google account
- /e/ version: 0.11
- Device model(s): FP3
Summary
In microg settings, the option Allow apps to find accounts is disabled (this was the default setting). However, it is still possible for unprivileged apps to figure out my account along with its email address.
The problem
Steps to reproduce
- Register a Google account in microg
- Edit your account settings in Settings > Accounts > Google and make sure the option Allow apps to find accounts is disabled
- Install Google Maps
- Start Google Maps and check the upper right corner
What is the current behavior?
Upper right corner displays the icon of my Google account. If I tap on it, a window will open which displays my email address.
What is the expected correct behavior?
Allow apps to find accounts should work as described. That is, Google Maps (or any other app) shouldn't be allowed to find my account and see its email address without prior authorization.
Technical informations
Relevant screenshots
Solutions
Workaround
Unregister Google account :-)