How Malicious Actors exploited Google Vulnerability, Exposed Users’ Phone Numbers and Bypassed 2FA

Date:

Share post:

A critical security flaw in Google’s account recovery system recently allowed malicious actors to obtain the full phone numbers of any Google user.

This was achieved through a sophisticated brute-force attack, as disclosed by a BruteCat security researcher this week. The vulnerability, which has since been patched, exploited a legacy Google username recovery form that operated without JavaScript.

How the Attack Worked

The core of the vulnerability lay in Google’s older username recovery system, designed to function even when JavaScript was disabled. A security researcher discovered that this overlooked system could be manipulated to confirm whether specific phone numbers were linked to particular Google display names, paving the way for systematic phone number enumeration.

The attack unfolded in three main steps:

Obtaining the Target’s Display Name: Attackers first acquired a target’s Google account display name. This was done by transferring document ownership in Looker Studio, which would leak the victim’s name without requiring any interaction from them.

Initiating Password Recovery: Next, the attackers would begin Google’s “forgot password” process. This step typically reveals a masked phone number hint (e.g., “ending in *XX”).

Brute-Forcing the Full Number: Finally, using a custom-built tool named “gpb,” the attackers brute-forced the complete phone number. This involved testing various combinations against the known display name and the masked phone number hint, as detailed in the BruteCat report.
Bypassing Google’s Protections

The researcher cleverly circumvented Google’s rate-limiting measures. They utilized vast IPv6 address ranges, offering over 18 quintillion unique IP addresses, to rotate through different addresses for each request. This effectively bypassed Google’s anti-abuse mechanisms.

Furthermore, the researcher discovered that “botguard” tokens from JavaScript-enabled forms could be repurposed for the No-JS version of the recovery system. This eliminated the need to solve CAPTCHA challenges, which would have otherwise prevented automated attacks.

Efficiency of the Attack

The attack proved remarkably efficient. The researcher reported achieving approximately 40,000 verification attempts per second using a modest server costing only $0.30 per hour. Depending on the country code, complete phone numbers could be extracted rapidly – from mere seconds for smaller countries like Singapore to around 20 minutes for larger countries such as the United States.

Google’s Response

Google was informed of the vulnerability on April 14, 2025, and responded swiftly. They implemented temporary mitigations while developing a permanent solution. By June 6, 2025, Google had fully deprecated the vulnerable No-JavaScript username recovery form, effectively eliminating the attack vector.

Google acknowledged the severity of the discovery, initially awarding a bug bounty of $1,337. Following an appeal from the researcher, who highlighted the attack’s lack of prerequisites and undetectable nature, the bounty was increased to $5,000.

This incident serves as a crucial reminder of the ongoing security challenges posed by legacy systems and underscores the importance of thorough security audits across all service endpoints, even those that seem obsolete or rarely used.

abridged from – Cyber Security News  By Guru Baran

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Related articles

Google Plus is officially gone after its mobile apps are rebranded as Google Currents

Google Plus, the company’s failed social network, is officially gone as of today. After Google Plus personal accounts...

Apply for the Google for Startups Black Founders Fund 2023

By Folarin Aiyegbusi, Head of Startup Ecosystem, Sub Saharan AfricaBlack founders in Africa are harnessing the power of...

2023 elections: Minister meets Google, Facebook on curbing fake news

The Minister of Information and Culture, Alhaji Lai Mohammed, has urged Google and Meta, owners of Facebook, WhatsApp...

Google Celebrates 5000 Entrepreneurs Graduates from Google’s Hustle Academy

By Hassan MuazGoogle on Tuesday held graduation events in Nigeria, Kenya and South Africa to celebrate 5000 business...