🧔♂️ A friendly human may check it before it goes live. More news here
Google fixes bug that leaked recovery phone numbers
A vulnerability in Google’s account recovery feature exposed private recovery phone numbers of numerous Google accounts, according to a security researcher. The issue, reported in April, has since been addressed by Google.
The researcher, operating under the handle “brutecat,” explained that the flaw involved a method to bypass Google’s anti-bot protections and rate limits.
By automating the process, the researcher could brute-force recovery phone numbers associated with Google accounts in less than 20 minutes. TechCrunch verified the exploit independently using a test account.
Google confirmed that the issue has been resolved.
“This issue has been fixed. We’ve always stressed the importance of working with the security research community through our vulnerability rewards program and we want to thank the researcher for flagging this issue,” said Google spokesperson Kimberly Samra.
The company noted there was no evidence that the vulnerability had been exploited.
🔗 Source: TechCrunch
🧠 Food for thought
1️⃣ Bug bounty programs have become critical infrastructure for tech security
Google’s $5,000 payment to the researcher highlights how bug bounty programs have evolved from niche initiatives to essential security infrastructure for major tech companies.
These programs enable companies to leverage the expertise of a diverse community of security researchers, creating a collaborative approach to cybersecurity that’s especially valuable during periods of increased threats 1.
The payment amount reflects the standardized reward tiers based on vulnerability severity that companies like Google, Microsoft, and Meta have established, with rewards sometimes reaching over €50,000 for critical findings 2.
This crowdsourced security model has proven particularly effective for discovering complex vulnerabilities like the “attack chain” described in this case, which required bypassing multiple security mechanisms that might have gone undetected by internal teams.
The structured vulnerability disclosure process ensures that critical bugs can be fixed before public disclosure, as demonstrated by TechCrunch’s decision to delay publishing until Google addressed the issue.
2️⃣ Phone numbers have become high-value targets for sophisticated attacks
Recovery phone numbers are particularly valuable to attackers because they serve as master keys to multiple services through password reset mechanisms and two-factor authentication 3.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




