Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Google Phone Number Leak: Security Update - News Directory 3

Google Phone Number Leak: Security Update

June 10, 2025 Catherine Williams Tech
News Context
At a glance
  • A⁤ now-patched vulnerability ⁤in Google ⁤accounts allowed attackers to possibly brute-force a user's⁤ recovery phone number.Knowing only a profile name and partial phone number, malicious actors could have...
  • The vulnerability resided in a deprecated, JavaScript-disabled version of Google's username recovery form, which lacked current anti-abuse protections.
  • BruteCat told BleepingComputer that the phone number retrieved via this attack is typically ‍the same as the account holder's primary number.
Original source: bleepingcomputer.com

key Points

  • Researcher discovered a flaw allowing⁣ phone number⁣ brute-forcing.
  • Attack exploited a deprecated Google username recovery form.
  • Google has since patched the vulnerability and issued a reward.

Google Account Flaw Exposed ⁣to Phone Number brute-Force Attacks

Updated June 10,⁣ 2025

A⁤ now-patched vulnerability ⁤in Google ⁤accounts allowed attackers to possibly brute-force a user’s⁤ recovery phone number.Knowing only a profile name and partial phone number, malicious actors could have exploited the ⁣flaw for ⁢phishing or SIM-swapping attacks.

The vulnerability resided in a deprecated, JavaScript-disabled version of Google’s username recovery form, which lacked current anti-abuse protections. Security researcher BruteCat discovered the issue. He previously revealed a flaw that could ‍expose YouTube account email addresses.

BruteCat told BleepingComputer that the phone number retrieved via this attack is typically ‍the same as the account holder’s primary number.

Brute-Forcing Technique

BruteCat accessed the legacy username recovery form and found that he could query ⁤whether a phone number was linked to a Google account using a profile display name. He bypassed rate-limiting defenses by rotating IPv6 addresses to generate trillions of unique source IPs. CAPTCHAs were circumvented using BotGuard tokens from the JS-enabled form.

Captured BotGuard token from a Google JS-enabled username recovery form
captured BotGuard token from a Google JS-enabled username recovery form
Source: BruteCat

brutecat developed a brute-forcing tool, “gpb,” that iterated through number ranges using country-specific formats and filtered out false positives. The tool leveraged Google’s ‘libphonenumber’ for ⁣valid number formats and a country mask database to identify phone formats by‍ region. A script generated botguard tokens via headless Chrome.

At a rate of 40,000 requests per second, the researcher estimated that ‍US numbers could be brute-forced in⁤ about 20 minutes, UK numbers in 4 minutes, and Netherlands numbers in under 15⁢ seconds.

Time to brute-force phone⁢ numbers
Time to brute-force phone numbers
Source: BruteCat

To initiate an attack, the target’s email address was needed. BruteCat found he could retrieve it by creating a Looker Studio document and transferring ownership to the target’s Gmail address, revealing their Google display name on ‍the⁢ creator’s dashboard.

While thousands‍ of accounts⁤ might share⁣ a profile name, the researcher narrowed down the search using the target’s partial phone number, obtained from Google’s account recovery workflow, which displays two⁤ digits of the recovery number.

“This time‍ can⁢ also be substantially reduced through phone number hints from password reset flows ⁣in other services such as PayPal, which provide several more digits (ex. +14•••••1779)”, said BruteCat.

Leaked phone numbers associated with Google accounts create a important security risk, potentially exposing users to targeted vishing or SIM swap attacks.

Bug Fixed

BruteCat reported his findings to Google on April 14, 2025, through the Vulnerability Reward Program (VRP). Initially deemed low risk, Google ⁢later upgraded the issue to “medium⁢ severity” on ⁣May 22, 2025, applied mitigations, and ⁤awarded the researcher $5,000.

Google confirmed the complete deprecation of⁤ the vulnerable no-JS recovery endpoint on June 6, 2025. The attack vector is now closed,but it is indeed unknown whether it was ever exploited maliciously.

What’s next

Users are encouraged to review their Google account security settings⁤ and ensure their recovery information is up-to-date. Google continues to monitor for potential vulnerabilities and encourages researchers to report any findings through its VRP.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

More on this

  • Fallout 76 Roadmap Details World Pets And Raven Rock Through 2027
  • €1,799: OPPO Find X10 Pro Max European Price Leaked
  • Why the Social Security COLA Is Announced in October (daybreakwire.com)
  • AZDOHS outlines Nonprofit Security Grant Program deadlines (archynewsy.com)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com