Close Menu
  • Home
  • AI
  • Business
  • Crypto
  • Entertainment
  • Finance
  • LIfe
  • Market
  • Sports
  • US
  • Tech

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Strength of 20 Years: Love Letter to TechCrunch

June 12, 2025

How to deploy robots to automate warehouse networks

June 12, 2025

Waymo Rides costs more than Uber or Lyft, and people pay anyway

June 12, 2025
Facebook X (Twitter) Instagram
XMcnx
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • Home
  • AI
  • Business
  • Crypto
  • Entertainment
  • Finance
  • LIfe
  • Market
  • Sports
  • US
  • Tech
XMcnx
Home » Google fixes bugs that could reveal users’ private phone numbers
Tech

Google fixes bugs that could reveal users’ private phone numbers

By supportJune 9, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Google Getty.jpg
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


Without warning the owner, security researchers can discover bugs that can be exploited to reveal the private recovery phone numbers for almost any Google account, putting users at privacy and security risks.

Google confirmed with TechCrunch that it fixed a bug after researchers warned the company in April.

An independent researcher who blogged his findings using Brutecat on the handle told TechCrunch that he could use bugs in the company’s account recovery feature to get a recovery phone number for a Google account.

The exploit relied on a “attack chain” of several individual processes working in tandem, including leaking the full display name of the target account and bypassing the anti-bot protection mechanism Google implemented to prevent malicious spam in password reset requests. Bypassing rate limits ultimately allowed researchers to cycle through any possible permutations of Google account phone numbers in a short time, reaching the correct number.

By automating the attack chain with scripts, the researchers said it is possible to brute force the recovery phone number of the Google account owner within 20 minutes, depending on the length of the phone number.

To test this, TechCrunch set up a new Google account using a phone number that has never been used before and provided Brutecat with the email address of the new Google account.

After a while, Brutecat sent a message with the phone number we had set up.

“Bingo:),” the researcher said.

By revealing your private recovery phone number, even anonymous Google accounts can be exposed to target attacks such as attempts to acquire. Identifying the private phone number associated with someone’s Google account can make it easier for a skilled hacker to control that phone number via a SIM swap attack. By controlling that phone number, an attacker can reset the password for the account associated with that phone number by generating a password reset code sent to the phone.

Given the potential risks to the wider public, TechCrunch agreed to keep this story until the bug was fixed.

“This issue has been fixed. We have always emphasized the importance of working with the security research community through our vulnerability rewards program. We would like to thank the researchers for flagging this issue.” “Such researcher submissions are one of many ways to quickly find and fix the issue for the sake of user safety.”

Samra said the company “will not expose any direct links that have been confirmed at this time.”

Brutecat said Google paid $5,000 in bug prize money for their discovery.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleApple’s new workout buddy helps you sweat smarter
Next Article Apple brings Apple Intelligence to iPhone screens with WWDC 2025
support

Related Posts

Tech

Strength of 20 Years: Love Letter to TechCrunch

By supportJune 12, 2025
Tech

Waymo Rides costs more than Uber or Lyft, and people pay anyway

By supportJune 12, 2025
Tech

Researchers confirm that two journalists have been hacked with Paragon Spyware

By supportJune 12, 2025
Tech

Snapchat unfolds a new $8.99 lens + subscription layer

By supportJune 12, 2025
Tech

How to delete 23andMe data

By supportJune 12, 2025
Tech

Tiktok’s biggest star was taken into custody on ice with the help of another influencer

By supportJune 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Strength of 20 Years: Love Letter to TechCrunch

By supportJune 12, 2025

TechCrunch is 20 years old. I somehow were here half that time, and this was…

How to deploy robots to automate warehouse networks

June 12, 2025

Waymo Rides costs more than Uber or Lyft, and people pay anyway

June 12, 2025

Researchers confirm that two journalists have been hacked with Paragon Spyware

June 12, 2025
Top Posts

Cancelling the Joy Reed Show is “mistakes”

February 26, 2025

Black melodrama has a possibility

February 26, 2025

The “Facts of Life” star died in 83

February 25, 2025

Cara Sophia Gascon joins Oscar despite social media controversy

February 25, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to XMcnx – your trusted source for insightful information about the world of Crypto, Market trends, the latest developments in the US, cutting-edge AI technologies, Tech innovations, and Finance.

At XMcnx, our mission is to provide you with timely, accurate, and relevant news and analyses that empower you to stay ahead in an ever-evolving digital world. We understand the challenges of navigating through the complexities of modern markets, technology, and financial systems. That’s why we’re dedicated to delivering high-quality content that helps you make informed decisions.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Strength of 20 Years: Love Letter to TechCrunch

June 12, 2025

How to deploy robots to automate warehouse networks

June 12, 2025

Waymo Rides costs more than Uber or Lyft, and people pay anyway

June 12, 2025
Most Popular

TikTok announces it will go dark on Sunday without ‘definitive’ guarantees

January 18, 2025

President Trump mints $31 billion in new official $TRUMP crypto meme coin

January 18, 2025

El Salvador’s secret weapon? Stacey Herbert talks about the company’s extensive Bitcoin education program

January 18, 2025
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 xmcnx. Designed by xmcnx.

Type above and press Enter to search. Press Esc to cancel.