Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

Funksec Ransomware Decryptor was published for free after the group was dormant

Skechers make kids shoes with hidden air tag compartments

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google fixes bugs that could reveal users’ private phone numbers
Startups

Google fixes bugs that could reveal users’ private phone numbers

userBy userJune 9, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Without warning the owner, security researchers can discover bugs that can be exploited to reveal the private recovery phone numbers for almost any Google account, putting users at privacy and security risks.

Google confirmed with TechCrunch that it fixed a bug after researchers warned the company in April.

An independent researcher who blogged his findings using Brutecat on the handle told TechCrunch that he could use bugs in the company’s account recovery feature to get a recovery phone number for a Google account.

The exploit relied on a “attack chain” of several individual processes working in tandem, including leaking the full display name of the target account and bypassing the anti-bot protection mechanism Google implemented to prevent malicious spam in password reset requests. Bypassing rate limits ultimately allowed researchers to cycle through any possible permutations of Google account phone numbers in a short time, reaching the correct number.

By automating the attack chain with scripts, the researchers said it is possible to brute force the recovery phone number of the Google account owner within 20 minutes, depending on the length of the phone number.

To test this, TechCrunch set up a new Google account using a phone number that has never been used before and provided Brutecat with the email address of the new Google account.

After a while, Brutecat sent a message with the phone number we had set up.

“Bingo:),” the researcher said.

By revealing your private recovery phone number, even anonymous Google accounts can be exposed to target attacks such as attempts to acquire. Identifying the private phone number associated with someone’s Google account can make it easier for a skilled hacker to control that phone number via a SIM swap attack. By controlling that phone number, an attacker can reset the password for the account associated with that phone number by generating a password reset code sent to the phone.

Given the potential risks to the wider public, TechCrunch agreed to keep this story until the bug was fixed.

“This issue has been fixed. We have always emphasized the importance of working with the security research community through our vulnerability rewards program. We would like to thank the researchers for flagging this issue.” “Such researcher submissions are one of many ways to quickly find and fix the issue for the sake of user safety.”

Samra said the company “will not expose any direct links that have been confirmed at this time.”

Brutecat said Google paid $5,000 in bug prize money for their discovery.


Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMeta of lectures investing more than $100 billion in Silicon Valley’s top AI startups
Next Article Two different botnets exploiting a vulnerability in Wazuh Server to launch a Mirai-based attack
user
  • Website

Related Posts

Skechers make kids shoes with hidden air tag compartments

July 30, 2025

2 How Uc Berkeley Dropout raised $28 million for AI Marketing Automation Startup

July 30, 2025

Observation continues to adapt to a changing world of software observability

July 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

Funksec Ransomware Decryptor was published for free after the group was dormant

Skechers make kids shoes with hidden air tag compartments

2 How Uc Berkeley Dropout raised $28 million for AI Marketing Automation Startup

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

TwinH Transforms Belgian Student Life: Hendrik’s Journey to Secure Digital Identity

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.