Cloud brute-force attack cracks Google users' phone numbers in minutes
ID: c64939e2-ecf4-5c7b-8d41-851675f50bf5
STIX ID: report--c64939e2-ecf4-5c7b-8d41-851675f50bf5
Feed Name: The Register (Security)
A security researcher (Brutecat) disclosed a flaw in Google's account recovery and Looker Studio integration that exposed users' phone numbers to a brute‑force enumeration attack. By creating a Looker Studio document, transferring ownership to a target, leveraging a legacy username recovery form that worked without JavaScript, and running an automated tool that validated candidate numbers, the researcher could unmask phone numbers tied to email addresses and demonstrated rapid enumeration times for several country codes; Google has since patched the issue and awarded a bug bounty.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
