Saturday, 1 November 2025
28.5 C
Singapore
25.1 C
Thailand
20.2 C
Indonesia
28.3 C
Philippines

Google patches security flaw that could expose users’ private phone numbers

Google has fixed a bug that allowed attackers to find users’ recovery phone numbers without their knowledge, raising privacy and security concerns.

A bug in Google’s account recovery system could have allowed someone to discover your private recovery phone number in less than 20 minutes—without you knowing. This flaw raised serious concerns about your security and privacy. Fortunately, Google has now fixed the issue after being alerted by a security researcher.

A hidden danger in account recovery

The vulnerability was discovered by an independent researcher known as brutecat. They found that the issue was linked to how Google’s account recovery system works when trying to reset a password. The researcher explained in a blog post that they could take advantage of a flaw in the recovery process to find the phone number connected to almost any Google account.

Using an “attack chain” made up of several steps, brutecat could leak an account’s full display name, bypass Google’s anti-bot systems, and cycle through every possible phone number combination. With this method, the attacker could eventually guess the correct number.

Google’s system has protections to prevent too many password reset requests from being made simultaneously, which usually prevents these brute-force attacks. However, brutecat was able to bypass those protections. By using a script to automate the process, they found it was possible to discover a recovery phone number in 20 minutes or less, depending on the number’s length.

Why this matters for your safety

Finding the phone number tied to your Google account might not be a big deal. But for hackers, it opens the door to dangerous follow-up attacks—especially SIM swap scams. In these attacks, someone tricks a phone company into giving them control of your phone number. Once they control your number, they can reset passwords and take over your online accounts, including email, bank accounts, and social media.

Even anonymous accounts, such as ones created for privacy reasons, could have been exposed if linked to a recovery phone number, making this flaw especially serious.

Google responds and rewards the discovery

Google confirmed that the issue had been fixed after brutecat reported it in April. “This issue has been fixed. We’ve always stressed the importance of working with the security research community through our vulnerability rewards program,” said Google spokesperson Kimberly Samra. “Researcher submissions like this are one of the many ways we’re able to quickly find and fix issues for the safety of our users.”

Samra added that there have been “no confirmed, direct links to exploits at this time,” meaning there’s no evidence yet that hackers took advantage of the bug before it was fixed.

As a thank you, Google rewarded brutecat with a US$5,000 bug bounty through its vulnerability rewards programme. This programme encourages security researchers to help Google spot flaws and fix them before they can be abused.

If you’re a Google user, you don’t need to do anything right now—Google has already fixed the issue. Still, it’s always a good idea to review your account’s security settings, enable two-factor authentication, and stay alert for any suspicious activity on your phone or accounts.

Hot this week

XDC Ventures acquires Contour Network and launches Stable-Coin Lab to reshape global trade finance

XDC Ventures acquires Contour Network and launches a Stable-Coin Lab to drive tokenised trade finance and faster cross-border settlements.

NTT DATA urges sustainability in AI development amid rising environmental concerns

NTT DATA’s white paper calls for sustainable AI development, highlighting solutions to reduce energy, water, and material consumption.

Neato cloud shutdown leaves robot vacuums limited to manual operation

Neato’s cloud services are shutting down, leaving its robot vacuums without app control and limited to manual operation.

Red Hat honours DBS and DIS for innovation at APAC Innovation Awards 2025

Red Hat recognises DBS Bank and Singapore’s Digital and Intelligence Service for AI and open source innovation at the 2025 APAC Awards.

OXS launches Thunder Duo on Kickstarter as first studio-grade gaming speakers with true Dolby Atmos

OXS launches Thunder Duo on Kickstarter, a studio-grade gaming speaker series with true Dolby Atmos, modular design, and immersive 360° sound.

Informatica unveils Fall 2025 release to power the era of agentic AI

Informatica’s Fall 2025 release introduces new AI-driven data management tools to power agentic AI with trusted enterprise data.

Commvault launches Data Rooms to connect enterprise data with AI platforms securely

Commvault introduces Data Rooms, a secure platform enabling enterprises to safely activate and share backup data for AI use.

Most organisations struggle to keep pace with AI-powered ransomware, says CrowdStrike survey

CrowdStrike’s 2025 survey reveals 76% of organisations struggle to keep up with AI-powered ransomware attacks.

VoidZero secures US$12.5 million Series A to launch unified JavaScript toolchain Vite+

VoidZero raises US$12.5 million Series A to launch Vite+, a unified JavaScript toolchain aimed at boosting developer productivity.

Related Articles