Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
Security IT

A Researcher Figured Out How To Reveal Any Phone Number Linked To a Google Account (wired.com) 11

A cybersecurity researcher was able to figure out the phone number linked to any Google account, information that is usually not public and is often sensitive, according to the researcher, Google, and 404 Media's own tests. From a report: The issue has since been fixed but at the time presented a privacy issue in which even hackers with relatively few resources could have brute forced their way to peoples' personal information. "I think this exploit is pretty bad since it's basically a gold mine for SIM swappers," the independent security researcher who found the issue, who goes by the handle brutecat, wrote in an email.

[...] In mid-April, we provided brutecat with one of our personal Gmail addresses in order to test the vulnerability. About six hours later, brutecat replied with the correct and full phone number linked to that account. "Essentially, it's bruting the number," brutecat said of their process. Brute forcing is when a hacker rapidly tries different combinations of digits or characters until finding the ones they're after. Typically that's in the context of finding someone's password, but here brutecat is doing something similar to determine a Google user's phone number.

Brutecat said in an email the brute forcing takes around one hour for a U.S. number, or 8 minutes for a UK one. For other countries, it can take less than a minute, they said. In an accompanying video demonstrating the exploit, brutecat explains an attacker needs the target's Google display name. They find this by first transferring ownership of a document from Google's Looker Studio product to the target, the video says. They say they modified the document's name to be millions of characters, which ends up with the target not being notified of the ownership switch. Using some custom code, which they detailed in their write up, brutecat then barrages Google with guesses of the phone number until getting a hit.

A Researcher Figured Out How To Reveal Any Phone Number Linked To a Google Account

Comments Filter:
  • More like an HR failure at Google. This is just insane.

  • It seems they all mess up. Time for real penalties large enough that make it worthwhile hiring actual experts and letting them do it right. Otherwise this crap will continue and it is getting unsustainable.

    • Yes.

      The people that don't give their phone numbers to random web services do.

      Or those who use throw-away phone numbers when they need to register a phone.

      • by gweihir ( 88907 )

        That is just dumb. The reason they want that phone number is because without it their crappy security gets _worse_.

        • You're not the sharpest tool in the drawer if you really think so.

          The real reason they want your mobile phone number is to track you.

          These tend to be unique and nearly permanent.

      • Most regular people won't have the knowledge of the tricks, or persistence to apply them at every login when google makes a point to tell you your account isn't safe without a number associated, and does not offer you an alternative on the screen. What I do when this happens is to ignore this screen, open another navigator tab, and it accepts it as an "ignored" answer.

        Also, there are websites that don't let you use the services without a phone number associated, e.g. banks, airlines, delivery services.

    • It seems they all mess up. Time for real penalties large enough that make it worthwhile hiring actual experts and letting them do it right. Otherwise this crap will continue and it is getting unsustainable.

      No, no one get security right, and they never will. Security is hard and even actual experts make mistakes.

      The best you can do is to expect companies to make a good effort to avoid vulnerabilities and to run vulnerability reward programs to incentivize researchers to look for and report bugs, then promptly reward the researchers and fix the vulns.

      And that's exactly what Google does, and what Google did. Google does hire lots of actual security experts and has lots of review processes intended to check

  • by Anonymous Coward

    I already knew security of 2FA using SMS was weak, but now it's been weakened even further.

    I'm glad I never have linked my phone number to my Google account, but Google still won't stop pestering me to do that even though it's clearly going to weaken the security of my account.

    Google, please stop asking for my phone number.

  • Actual link (Score:4, Informative)

    by juancn ( 596002 ) on Monday June 09, 2025 @01:24PM (#65437895) Homepage

    Actual content: Bruteforcing the phone number of any Google user [brutecat.com]

    Not that 404 paywalled crap.

"Trust me. I know what I'm doing." -- Sledge Hammer

Working...