G Suite - Device Management XSS
In G Suite business, you can manage other users devices. These devices include iOS, Android, Chrome and also networks like VPNs, WiFi, Ethernet. This specific issue was found in Chrome management.
Chrome management is particularly interesting. It is mostly used in Chrome books and is quite common among school districts in United States. Administrators can control different features of Chrome with this. For example: blocking developer console, URL whitelist, password management, bookmark sync.
All of these informations are then synced when user use chrome with the organization email. This can be done by going to Chrome settings and selecting: “Add profile”. Once the profile is added, all the information from the chrome settings is synced to that user’s chrome. One such information is Bookmarks.