Google Phone Number Leak: Security Update
- A now-patched vulnerability in Google accounts allowed attackers to possibly brute-force a user's recovery phone number.Knowing only a profile name and partial phone number, malicious actors could have...
- The vulnerability resided in a deprecated, JavaScript-disabled version of Google's username recovery form, which lacked current anti-abuse protections.
- BruteCat told BleepingComputer that the phone number retrieved via this attack is typically the same as the account holder's primary number.
Google Account Flaw Exposed to Phone Number brute-Force Attacks
A now-patched vulnerability in Google accounts allowed attackers to possibly brute-force a user’s recovery phone number.Knowing only a profile name and partial phone number, malicious actors could have exploited the flaw for phishing or SIM-swapping attacks.
The vulnerability resided in a deprecated, JavaScript-disabled version of Google’s username recovery form, which lacked current anti-abuse protections. Security researcher BruteCat discovered the issue. He previously revealed a flaw that could expose YouTube account email addresses.
BruteCat told BleepingComputer that the phone number retrieved via this attack is typically the same as the account holder’s primary number.
Brute-Forcing Technique
BruteCat accessed the legacy username recovery form and found that he could query whether a phone number was linked to a Google account using a profile display name. He bypassed rate-limiting defenses by rotating IPv6 addresses to generate trillions of unique source IPs. CAPTCHAs were circumvented using BotGuard tokens from the JS-enabled form.

Source: BruteCat
brutecat developed a brute-forcing tool, “gpb,” that iterated through number ranges using country-specific formats and filtered out false positives. The tool leveraged Google’s ‘libphonenumber’ for valid number formats and a country mask database to identify phone formats by region. A script generated botguard tokens via headless Chrome.
At a rate of 40,000 requests per second, the researcher estimated that US numbers could be brute-forced in about 20 minutes, UK numbers in 4 minutes, and Netherlands numbers in under 15 seconds.

Source: BruteCat
To initiate an attack, the target’s email address was needed. BruteCat found he could retrieve it by creating a Looker Studio document and transferring ownership to the target’s Gmail address, revealing their Google display name on the creator’s dashboard.
While thousands of accounts might share a profile name, the researcher narrowed down the search using the target’s partial phone number, obtained from Google’s account recovery workflow, which displays two digits of the recovery number.
“This time can also be substantially reduced through phone number hints from password reset flows in other services such as PayPal, which provide several more digits (ex. +14•••••1779)”, said BruteCat.
Leaked phone numbers associated with Google accounts create a important security risk, potentially exposing users to targeted vishing or SIM swap attacks.
Bug Fixed
BruteCat reported his findings to Google on April 14, 2025, through the Vulnerability Reward Program (VRP). Initially deemed low risk, Google later upgraded the issue to “medium severity” on May 22, 2025, applied mitigations, and awarded the researcher $5,000.
Google confirmed the complete deprecation of the vulnerable no-JS recovery endpoint on June 6, 2025. The attack vector is now closed,but it is indeed unknown whether it was ever exploited maliciously.
What’s next
Users are encouraged to review their Google account security settings and ensure their recovery information is up-to-date. Google continues to monitor for potential vulnerabilities and encourages researchers to report any findings through its VRP.
