By having a user’s profile name and an easily recovered partial phone number, researchers could brute-force the recovery phone number for any Google account, increasing the danger of phishing and SIM-swapping assaults.
The attack technique entails leveraging an outdated version of the Google login recovery form that was disabled by JavaScript and lacked contemporary anti-abuse safeguards.
Security researcher BruteCat, who showed in February that it is easy to reveal the private email addresses of YouTube accounts, found the vulnerability.
Although the assault recovers the phone number users have set up for Google account recovery, BruteCat told BleepingComputer that in the great majority of situations, this is the same as the account holder’s primary phone number read more about Google patched bug leaking phone numbers tied to accounts
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
