Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Google fixes bug that leaked recovery phone numbers

A vulnerability in Google’s account recovery feature exposed private recovery phone numbers of numerous Google accounts, according to a security researcher. The issue, reported in April, has since been addressed by Google.

The researcher, operating under the handle “brutecat,” explained that the flaw involved a method to bypass Google’s anti-bot protections and rate limits.

By automating the process, the researcher could brute-force recovery phone numbers associated with Google accounts in less than 20 minutes. TechCrunch verified the exploit independently using a test account.

Google confirmed that the issue has been resolved.

“This issue has been fixed. We’ve always stressed the importance of working with the security research community through our vulnerability rewards program and we want to thank the researcher for flagging this issue,” said Google spokesperson Kimberly Samra.

The company noted there was no evidence that the vulnerability had been exploited.

🔗 Source: TechCrunch


🧠 Food for thought

1️⃣ Bug bounty programs have become critical infrastructure for tech security

Google’s $5,000 payment to the researcher highlights how bug bounty programs have evolved from niche initiatives to essential security infrastructure for major tech companies.

These programs enable companies to leverage the expertise of a diverse community of security researchers, creating a collaborative approach to cybersecurity that’s especially valuable during periods of increased threats 1.

The payment amount reflects the standardized reward tiers based on vulnerability severity that companies like Google, Microsoft, and Meta have established, with rewards sometimes reaching over €50,000 for critical findings 2.

This crowdsourced security model has proven particularly effective for discovering complex vulnerabilities like the “attack chain” described in this case, which required bypassing multiple security mechanisms that might have gone undetected by internal teams.

The structured vulnerability disclosure process ensures that critical bugs can be fixed before public disclosure, as demonstrated by TechCrunch’s decision to delay publishing until Google addressed the issue.

2️⃣ Phone numbers have become high-value targets for sophisticated attacks

Recovery phone numbers are particularly valuable to attackers because they serve as master keys to multiple services through password reset mechanisms and two-factor authentication 3.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.