A security researcher discovered a bug in Google's URL parsing library, which allowed them to bypass domain validation and potentially steal API keys or OAuth Client IDs. The bug was caused by a flawed assumption in a regular expression used for domain validation. The researcher found that the bug was not only present in the initial application they were testing, but also in many other Google products. The bug was reported to Google and fixed, with the researcher receiving a $6,000 bounty.