The following YouTube video talks about Google session hijacking from Gmail.
I usually think that the owner of a website can not initiate hacking (in modern browsers, excluding short-term critical bugs), otherwise the website would be very dangerous.
There are 2 points in the video about which I am skeptical. Are the following possible (providing important information)?
- Clicking a link in Gmail can lead to a Google session hijacking.
- Downloading a file can cause it to run in the background.