logo

Google bug allowed phone number of almost any user to be discovered

ID: de04dfeb-019e-59df-9afc-c718478d0abd

STIX ID: report--de04dfeb-019e-59df-9afc-c718478d0abd

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-06-10

Date Updated: 2026-04-28

...
...

A security researcher (Brutecat) discovered and demonstrated two Google flaws: one in the account-recovery flow that allowed an attacker to enumerate users' recovery phone numbers at scale (using IP rotation, CAPTCHA bypasses, and libphonenumber to generate candidates), and another in Looker Studio where transferring document ownership to a target caused the victim's full display name to appear publicly. Google patched the issues and said it is unaware of any confirmed exploitation, but the flaws posed a serious phishing and SIM‑swap risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.