Sunday, 10 August 2025
29.4 C
Singapore
32.6 C
Thailand
20.1 C
Indonesia
28.4 C
Philippines

Google patches security flaw that could expose users’ private phone numbers

Google has fixed a bug that allowed attackers to find users’ recovery phone numbers without their knowledge, raising privacy and security concerns.

A bug in Google’s account recovery system could have allowed someone to discover your private recovery phone number in less than 20 minutes—without you knowing. This flaw raised serious concerns about your security and privacy. Fortunately, Google has now fixed the issue after being alerted by a security researcher.

A hidden danger in account recovery

The vulnerability was discovered by an independent researcher known as brutecat. They found that the issue was linked to how Google’s account recovery system works when trying to reset a password. The researcher explained in a blog post that they could take advantage of a flaw in the recovery process to find the phone number connected to almost any Google account.

Using an “attack chain” made up of several steps, brutecat could leak an account’s full display name, bypass Google’s anti-bot systems, and cycle through every possible phone number combination. With this method, the attacker could eventually guess the correct number.

Google’s system has protections to prevent too many password reset requests from being made simultaneously, which usually prevents these brute-force attacks. However, brutecat was able to bypass those protections. By using a script to automate the process, they found it was possible to discover a recovery phone number in 20 minutes or less, depending on the number’s length.

Why this matters for your safety

Finding the phone number tied to your Google account might not be a big deal. But for hackers, it opens the door to dangerous follow-up attacks—especially SIM swap scams. In these attacks, someone tricks a phone company into giving them control of your phone number. Once they control your number, they can reset passwords and take over your online accounts, including email, bank accounts, and social media.

Even anonymous accounts, such as ones created for privacy reasons, could have been exposed if linked to a recovery phone number, making this flaw especially serious.

Google responds and rewards the discovery

Google confirmed that the issue had been fixed after brutecat reported it in April. “This issue has been fixed. We’ve always stressed the importance of working with the security research community through our vulnerability rewards program,” said Google spokesperson Kimberly Samra. “Researcher submissions like this are one of the many ways we’re able to quickly find and fix issues for the safety of our users.”

Samra added that there have been “no confirmed, direct links to exploits at this time,” meaning there’s no evidence yet that hackers took advantage of the bug before it was fixed.

As a thank you, Google rewarded brutecat with a US$5,000 bug bounty through its vulnerability rewards programme. This programme encourages security researchers to help Google spot flaws and fix them before they can be abused.

If you’re a Google user, you don’t need to do anything right now—Google has already fixed the issue. Still, it’s always a good idea to review your account’s security settings, enable two-factor authentication, and stay alert for any suspicious activity on your phone or accounts.

Hot this week

How personal AI is turning your smartphone into an assistant editor and creative partner

Discover how personal AI transforms your smartphone into an assistant, editor, and creative partner, enhancing daily life with smart features.

Apple develops in-house AI chatbot to rival ChatGPT

Apple forms new team to develop stripped-down AI chatbot, marking shift from ChatGPT partnership to in-house innovation.

Nintendo sets new milestone as Switch 2 surpasses 5.8 million units sold in debut month

Nintendo Switch 2 sells over 5.8 million units in June, making it the company’s fastest-selling console ever.

Lenovo to host largest-ever Tech World event at CES 2026 in Las Vegas

Lenovo brings Tech World to CES 2026 at Sphere in Las Vegas, unveiling AI innovations and new partnerships with FIFA and Formula 1.

JMEV enters the Singapore market with its new Elight electric sedan

Chinese EV brand JMEV debuts in Singapore with the Elight electric sedan, priced from S$216,888 and offering a range of up to 600km.

Xiaomi launches Mijia washer dryer in Singapore

Xiaomi launches the Mijia Front Load Washer Dryer 10.5kg in Singapore, offering hygienic cleaning, smart controls, and compact design for modern homes.

Tokyo Electron under scrutiny following alleged TSMC trade secrets theft

Tokyo Electron faces scrutiny after a former employee was arrested in Taiwan for allegedly stealing TSMC trade secrets.

Meta unveils cutting-edge prototype headsets showcasing the future of mixed reality

Meta’s new VR prototypes preview the future of immersive tech with major leaps in realism, resolution, and field of view.

Apple to collaborate with Samsung on iPhone image sensors in Texas

Apple partners with Samsung to produce next-generation iPhone image sensors in Texas, utilising new chip technology amid the US supply chain expansion.

Related Articles

Popular Categories