Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Republican proposal supported by Trump floats $1,000 baby bonds for families

IONQ acquires nearly $1.1 billion in British quantum startup Oxford Ionics

White House budget requests cut tribal college and university funding

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Google fixes bugs that could reveal users’ private phone numbers
Startups

Google fixes bugs that could reveal users’ private phone numbers

userBy userJune 9, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Without warning the owner, security researchers can discover bugs that can be exploited to reveal the private recovery phone numbers for almost any Google account, putting users at privacy and security risks.

Google confirmed with TechCrunch that it fixed a bug after researchers warned the company in April.

An independent researcher who blogged his findings using Brutecat on the handle told TechCrunch that he could use bugs in the company’s account recovery feature to get a recovery phone number for a Google account.

The exploit relied on a “attack chain” of several individual processes working in tandem, including leaking the full display name of the target account and bypassing the anti-bot protection mechanism Google implemented to prevent malicious spam in password reset requests. Bypassing rate limits ultimately allowed researchers to cycle through any possible permutations of Google account phone numbers in a short time, reaching the correct number.

By automating the attack chain with scripts, the researchers said it is possible to brute force the recovery phone number of the Google account owner within 20 minutes, depending on the length of the phone number.

To test this, TechCrunch set up a new Google account using a phone number that has never been used before and provided Brutecat with the email address of the new Google account.

After a while, Brutecat sent a message with the phone number we had set up.

“Bingo:),” the researcher said.

By revealing your private recovery phone number, even anonymous Google accounts can be exposed to target attacks such as attempts to acquire. Identifying the private phone number associated with someone’s Google account can make it easier for a skilled hacker to control that phone number via a SIM swap attack. By controlling that phone number, an attacker can reset the password for the account associated with that phone number by generating a password reset code sent to the phone.

Given the potential risks to the wider public, TechCrunch agreed to keep this story until the bug was fixed.

“This issue has been fixed. We have always emphasized the importance of working with the security research community through our vulnerability rewards program. We would like to thank the researchers for flagging this issue.” “Such researcher submissions are one of many ways to quickly find and fix the issue for the sake of user safety.”

Samra said the company “will not expose any direct links that have been confirmed at this time.”

Brutecat said Google paid $5,000 in bug prize money for their discovery.


Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMeta of lectures investing more than $100 billion in Silicon Valley’s top AI startups
Next Article Two different botnets exploiting a vulnerability in Wazuh Server to launch a Mirai-based attack
user
  • Website

Related Posts

Waymo Robotaxis, LIME E-SCOOTERS, flares amid LA protests

June 9, 2025

Investors are encouraged to fund gender, drugs and other social taboo products

June 9, 2025

Axiom Space is preparing for its fourth mission to the ISS

June 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Republican proposal supported by Trump floats $1,000 baby bonds for families

IONQ acquires nearly $1.1 billion in British quantum startup Oxford Ionics

White House budget requests cut tribal college and university funding

Reed & McKay announces new CEOs when Fred Stratford retires

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

IONQ acquires nearly $1.1 billion in British quantum startup Oxford Ionics

Meta of lectures investing more than $100 billion in Silicon Valley’s top AI startups

Galaxy Ventures Backs Rise Chain, $8 million raised to launch the fastest zone for real-time apps on Ethereum

Qualcomm acquires Alphawave for $2.4 billion and expands into the AI ​​data center market

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.