HomeUpdatesBug fix that exposed phone numbers connected to Google accounts

Fixed a bug that exposed phone numbers connected to Google accounts

A serious vulnerability in Google's account recovery mechanism allowed users' phone numbers to be revealed through brute-force techniques, creating a dangerous opening for phishing and SIM-swapping attacks. All that was needed was the public profile name and a few digits of their phone number.

Google accounts phone numbers

The attack, carried out by researchers, exploited an outdated version of Google's username recovery form — one without modern checks and protections — which continued to accept POST requests, allowing the attacker to verify whether a number matched a specific account.

The flaw was discovered by security researcher BruteCat, who earlier this year uncovered another security flaw that could have exposed private email addresses of YouTube users.

See also: SK Telecom says 3-year-old breach affected 27 million numbers

According to BruteCat, the phone numbers exposed by the attack were intended for account recovery, but in the majority of cases they are identical to the user's primary contact number.

Brute-forcing recovery numbers Google

BruteCat discovered that he could access an older (no-JavaScript) username retrieval form, which appeared to be working properly. The form allowed for searching for information about whether a phone number was associated with a Google account based on a user's profile display name (this was done via two POST requests).

The researcher bypassed basic defenses in the form by using IPv6 address rotation to generate trillions of unique source IPs across /64 subnets for these requests.

CAPTCHAs displayed by many requests were bypassed by replacing the 'bgresponse=js_disabled' parameter with a valid BotGuard token from the JS-enabled form.

BruteCat developed a specialized brute-forcing tool, called gpb, which performs brute-force scanning of phone numbers based on country-specific number formats. The tool incorporates filters to eliminate false positives and relies on libphonenumber to generate valid numbers per region. He also developed a country mask database and a script to generate BotGuard tokens via headless Chrome.

See also: OpenAI: Registering on ChatGPT with just a phone number?

The efficiency of the method is impressive: with a brute-forcing rate of 40,000 requests per second, the number disclosure process per country takes only 20 minutes for the USA, 4 minutes for the United Kingdom, and less than 15 seconds for the Netherlands.

To launch such an attack, the email address target's, but Google has been hiding this information from the recovery form since 2024. However, BruteCat found a way to recover it: by creating a document in Looker Studio and transferring ownership to the target's Gmail account. This results in the user's full Google name in the creator's dashboard, without any interaction or notification to the victim.

With a target's email address, it's possible to run repeated requests to find all the phone numbers associated with a profile's display name. While a single name could yield thousands of potential accounts, the method's accuracy was boosted by using a few digits from the user's phone number. To extract these digits, the researcher took advantage of Google's account recovery system, which reveals two digits of the recovery phone. Additionally, as BruteCat explains, the process can be done faster through password resets on other services, such as PayPal, which display more digits.

Fixed a bug that exposed phone numbers connected to Google accounts

Revealing phone numbers associated with Google accounts poses serious security risks. Users become vulnerable to attacks vishing (voice phishing), as well as SIM swapping – a form of fraud that can lead to complete loss of control of an account.

Google's response: Rejection, upgrade and remediation

BruteCat officially filed its report with Google through the Vulnerability Reward Program (VRP) on April 14, 2025. Although the company initially rated the threat as “low severity,” it reconsidered its stance and upgraded it to “moderate severity” on May 22. It also began implementing temporary mitigations and rewarded the researcher with $5,000 for the discovery.

See also: Telegram: Will give phone numbers and IP addresses of users to the authorities

On June 6, 2025, Google confirmed that the vulnerable no-JS recovery endpoint was completely disabled, preventing any future exploitation via the method in question.

While there is currently no evidence of malicious use of this particular security flaw, it remains unknown whether the vulnerability has been used in the past by threat actors.

The fact that Google did not immediately fix the problem and initially downplayed it shows how fragile security can be even at tech giants. The final patch and closure of the vulnerability are certainly positive steps, but it highlights the need for constant vigilance and rapid response to such threats.

Overall, the attack highlights how important it is for users not to rely solely on a single security factor and to be cautious of any unusual communication that concerns their phone numbers or accounts.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS