logo

Google Bug Allowed Brute-Forcing of Any User Phone Number

ID: 4036b321-60d4-5cb3-a509-70182a098f64

STIX ID: report--4036b321-60d4-5cb3-a509-70182a098f64

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-06-11

Date Updated: 2026-04-21

...
...

A researcher discovered and reported a vulnerability in Google’s password-recovery No-JS form that allowed enumeration of recovery phone numbers and, via a Looker Studio ownership trick, leakage of full display names. Because the No-JS form did not invoke BotGuard, the researcher crafted chained POST requests and used IP/IPv6 rotation plus CAPTCHA bypass techniques to perform high-rate checks; Google patched the issue globally and paid a $5,000 bug bounty, and there is no known evidence of active exploitation, though the flaw could enable large-scale phishing and SIM-swap attacks if abused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.