Google shuts off Chrome Sync API for third-party browsers on Android, citing a security vulnerability

A bug report was filed on January 3 on the Chromium bug tracker, explaining that attempting to sign-in with Chromium builds on Android resulted in an 'INVALID_SCOPE' error. After many reported the same issue, the likely cause was found - a recent change to how scoped refresh tokens were handled. This meant that only official Chrome builds could request tokens, and it only affects Android (Chromium builds on the desktop continue to work normally).
The last comment on the bug report.
The report was closed yesterday by a Chrome developer, explaining that access to the Sync API was locked down "to address a security vulnerability." The developer went on to say that Chrome Sync was never officially supported for third party browsers, and that Google does not intend to create a whitelist solution where users/developers can request refresh tokens.
Comments
Post a Comment