25/05/2026
Vulnerability Accepted – Security Research Update
I’m pleased to share that my recently reported vulnerability has been officially accepted for further assessment and remediation through a structured security review process.
This vulnerability was identified in an account lifecycle and session management flow within a cloud-based system.
⸻
Vulnerability Details:
The issue was related to improper data handling after account deletion. It was observed that:
• After account deletion, user session remained active under certain conditions
• User-related data (such as contact entries and Gmail/contact information) was still accessible
• Data added before deletion remained visible even after the account was deleted
• In some cases, new data could still be added and persisted after deletion
This behavior indicates that user data was not being fully cleared or invalidated upon account deletion, leading to potential data persistence and privacy exposure risks.
⸻
Security Impact:
Under specific authenticated scenarios, this could potentially lead to:
* Unauthorized access to residual user data
* Privacy exposure of stored contact information
* Incomplete account data removal behavior
From a security standpoint, this aligns with a medium to high severity (P2-level) issue depending on impact assessment.
⸻
💰 Bug Bounty Context:
In the Company , vulnerabilities of this nature in cloud and application systems are typically rewarded under structured bug bounty programs, where payouts can range from $100 up to $5,000 or more, depending on severity, scope, and impact.
Given the nature of this issue and the fact that it has now been accepted and moved into the remediation phase, I appreciate the structured handling of security reports and hope for a fair evaluation and reward aligned with the impact.
⸻
Looking forward to the final resolution and continuing my journey in responsible vulnerability research.