Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Skip to content

Privacy breach: apps can figure out the email address from my Google account

  • /e/ version: 0.11
  • Device model(s): FP3

Summary

In microg settings, the option Allow apps to find accounts is disabled (this was the default setting). However, it is still possible for unprivileged apps to figure out my account along with its email address.

The problem

Steps to reproduce

  1. Register a Google account in microg
  2. Edit your account settings in Settings > Accounts > Google and make sure the option Allow apps to find accounts is disabled
  3. Install Google Maps
  4. Start Google Maps and check the upper right corner

What is the current behavior?

Upper right corner displays the icon of my Google account. If I tap on it, a window will open which displays my email address.

What is the expected correct behavior?

Allow apps to find accounts should work as described. That is, Google Maps (or any other app) shouldn't be allowed to find my account and see its email address without prior authorization.

Technical informations

Relevant screenshots

microG_Services_Core

Maps

Solutions

Workaround

Unregister Google account :-)