Google Bug Allowed Brute-Forcing of Any User Phone Number
ID: 4036b321-60d4-5cb3-a509-70182a098f64
STIX ID: report--4036b321-60d4-5cb3-a509-70182a098f64
Feed Name: Dark Reading
A researcher discovered and reported a vulnerability in Google’s password-recovery No-JS form that allowed enumeration of recovery phone numbers and, via a Looker Studio ownership trick, leakage of full display names. Because the No-JS form did not invoke BotGuard, the researcher crafted chained POST requests and used IP/IPv6 rotation plus CAPTCHA bypass techniques to perform high-rate checks; Google patched the issue globally and paid a $5,000 bug bounty, and there is no known evidence of active exploitation, though the flaw could enable large-scale phishing and SIM-swap attacks if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
