Google bug allowed phone number of almost any user to be discovered
ID: de04dfeb-019e-59df-9afc-c718478d0abd
STIX ID: report--de04dfeb-019e-59df-9afc-c718478d0abd
Feed Name: Malwarebytes Blog
A security researcher (Brutecat) discovered and demonstrated two Google flaws: one in the account-recovery flow that allowed an attacker to enumerate users' recovery phone numbers at scale (using IP rotation, CAPTCHA bypasses, and libphonenumber to generate candidates), and another in Looker Studio where transferring document ownership to a target caused the victim's full display name to appear publicly. Google patched the issues and said it is unaware of any confirmed exploitation, but the flaws posed a serious phishing and SIM‑swap risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
