I also did a subdomain search on google a few weeks ago. I stumbled upon a lot of login sites.
A subdomain search leaded to 95 subdomains under corp.google.com.
There is some strange javascript in those pages, there is a function called riskMi.
I don't want to get sucked into it, I'm also closing the tab and going back to my terminal :).
I guess it's as much mindset as it's skill.
If instead of just complaining that commenter had taken the time to fill out a bug report they could have easily gotten the bounty instead.
Sometimes it just takes a tiny bit of extra effort to go from noticing something's amiss to actually doing something to get it fixed.
Basically, Chrome allowed users to use the "Always open files of this type" option with executable files. So if anyone was ever foolish enough to set that option after downloading a `.exe` on Windows, any future site they visited could take over their machine just by initiating a download for a malicious executable.