NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Google fixes bug that exposed private phone numbers
    Summarize
    Next Article
    Google fixes bug that exposed private phone numbers
    The issue enabled automated brute‑force attacks using simple scripts

    Google fixes bug that exposed private phone numbers

    By Mudit Dube
    Jun 10, 2025
    09:41 am

    What's the story

    Google has patched a critical bug that allowed attackers to expose private recovery phone numbers tied to Google accounts.

    A security researcher known as brutecat uncovered the flaw in the legacy username recovery form in mid-April and reported it to the tech giant.

    The issue enabled automated brute‑force attacks using simple scripts.

    Google has now fully disabled the vulnerable endpoint and issued a fix to protect user privacy.

    Attack details

    How the exploit worked

    The exploit involved an "attack chain" of multiple processes, including leaking the full display name of a targeted account.

    It also bypassed an anti-bot protection mechanism that Google had put in place to stop malicious password reset requests from being spammed.

    By bypassing this rate limit, brutecat was able to quickly cycle through every possible combination of a Google account's phone number and find the right one within minutes.

    Risk assessment

    Script automated the attack chain

    The researcher automated the attack chain with a script, making it possible to brute-force a Google account owner's recovery phone number in less than 20 minutes.

    TechCrunch tested this by creating a new Google account with an unused phone number and giving brutecat its email address.

    The researcher was able to reveal the private recovery phone number within minutes, confirming the vulnerability of even anonymous Google accounts to targeted attacks like takeover attempts.

    Bug bounty

    Google has fixed the issue

    A Google spokesperson confirmed that the issue has been resolved and thanked the researcher for bringing it to their attention through their vulnerability rewards program.

    The company has not seen "any confirmed, direct links to exploits at this time."

    For their discovery, brutecat received a $5,000 bug bounty from Google.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Google
    Cybercrimes

    Latest

    Google fixes bug that exposed private phone numbers Google
    WWDC 2025: Apple's top 7 announcements you need to know  Apple
    Nicholas Pooran clocked these prominent records in T20I cricket  Nicholas Pooran
    LA protests; Trump deploys another 2,000 National Guard troops, Marines California

    Google

    Google finally launches Wear OS 6 with Material 3 design Samsung
    Google's latest tool can identify content generated by AI  Microsoft
    Google launches $250/month subscription plan for advanced AI tools Google Drive
    Google Chrome will now automatically change your compromised passwords Google Chrome

    Cybercrimes

    Beware! Cybercriminals are using AI voices to steal Gmail credentials Gmail
    Grubhub suffers data breach, personal details of users compromised Data Leak
    Fake apps posing as LIC now, be careful Life Insurance Corporation of India
    What is 'zero-click hack' and how to protect yourself WhatsApp
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025