Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Crunchyroll confirms data breach after hackers claim unauthorized access

Insight Partners removes investment post for Delve amid ‘false compliance’ claims.

Zoox is bringing its robotaxis to Austin and Miami

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Mirage raises $75M to continue building models for AI video editing app Captions

    24 March 2026

    Bernie Sanders’ AI ‘gotcha’ video fails, but the memes are great

    24 March 2026

    Are AI tokens the new signing bonus or just a cost of doing business?

    23 March 2026

    Want to build a robot snowman?

    23 March 2026

    Why Wall Street Didn’t Win Nvidia’s Big Conference

    22 March 2026
  • Apps

    Pinterest is launching a new feature for promoting a Pin

    24 March 2026

    Apple Maps may receive advertisements

    24 March 2026

    Facebook is launching a new monetization program to attract popular creators from TikTok, YouTube

    23 March 2026

    Apps that distract you from the endless cycle of scrolling

    23 March 2026

    The features powered by Gemini in Google Workspace that are worth using

    22 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026

    Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

    16 March 2026
  • Hardware

    Ultrahuman boosts US push with Ring Pro as Oura tightens its grip

    24 March 2026

    Amazon is working on a new smartphone with Alexa at its core, the report says

    20 March 2026

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026

    MacBook Neo, AirPods Max 2, iPhone 17e and everything else Apple announced this month

    18 March 2026

    Oura enters India’s smart ring market with Ring 4

    17 March 2026
  • Media & Entertainment

    Tubi joins forces with popular TikTokers to create original streaming content

    19 March 2026

    Patreon CEO calls AI companies’ fair use argument ‘bogus’, says creators should be paid

    18 March 2026

    Meet Vurt, the first mobile streaming platform for indie filmmakers embracing vertical video

    18 March 2026

    BuzzFeed debuts AI applications for new revenue

    17 March 2026

    Facebook makes it easy for creators to report copycats

    14 March 2026
  • Security

    Crunchyroll confirms data breach after hackers claim unauthorized access

    24 March 2026

    Delve halts demos, Insight Partners sheds investment position amid ‘false compliance’ claims

    24 March 2026

    The FBI says Iranian hackers are using Telegram to steal data in malware attacks

    23 March 2026

    Delve accused of misleading customers with ‘false compliance’

    22 March 2026

    Delve accused of misleading customers with ‘false compliance’

    21 March 2026
  • Startups

    Insight Partners removes investment post for Delve amid ‘false compliance’ claims.

    24 March 2026

    Bengaluru food delivery startup Swish raises $38 million, its third round in 18 months

    24 March 2026

    Cursor admits that his new coding model was built on top of Moonshot AI’s Kimi

    23 March 2026

    Microsoft hires Sequoia-backed AI collaboration platform team Cove

    21 March 2026

    Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

    20 March 2026
  • Transportation

    Zoox is bringing its robotaxis to Austin and Miami

    24 March 2026

    Zipline raises another $200 million to fuel drone delivery expansion

    24 March 2026

    TechCrunch Mobility: Uber everywhere, at once

    23 March 2026

    The SEC ends its four-year investigation into EV startup Faraday Future

    23 March 2026

    Uber taps Rivian to build robotaxis in deal worth up to $1.25 billion

    22 March 2026
  • Venture

    Startup Gimlet Labs solves the AI ​​inference problem in a surprisingly elegant way

    24 March 2026

    AI startups are eating up the venture industry, and the returns, so far, are good

    21 March 2026

    Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

    19 March 2026

    AI ‘boys club’ could widen wealth gap for women, says Rana el Kaliouby

    18 March 2026

    Billionaires made a promise – now some want to leave

    17 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Google Fixes error that could reveal user’s private phone numbers
Security

Google Fixes error that could reveal user’s private phone numbers

techtost.comBy techtost.com11 June 202503 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Google Fixes Error That Could Reveal User's Private Phone Numbers
Share
Facebook Twitter LinkedIn Pinterest Email

A security researcher has discovered an error that could exploit to reveal the private recovery phone number almost any Google account without notifying its owner, possibly exposing users to privacy and security risks.

Google confirmed to TechCrunch that it has set the error after the researcher warned the company in April.

The independent researcher, who goes by the Brutecat handle and blogged their findingsHe told TechCrunch that they could obtain the recovery phone number of a Google Account, taking advantage of an error in the company’s account recovery mode.

The exploitation was based on a “attack chain” of many individual procedures that work in parallel, including the full display of a targeted account and bypassing a BOT protection mechanism implemented by Google to prevent malicious spamming. Bypassing the interest rate threshold eventually allowed the researcher to release through any possible transfer of the Google account phone number in a short period of time and reach the right digits.

By automating the attack chain with a scenario, the researcher said it was possible to inflate Google’s holder’s recovery phone number in 20 minutes or less, depending on the length of the phone number.

To try this, TechCrunch founded a new Google account with a phone number that had never been used before, then provided the Brutecat the new Google account address.

A little later, Brutecat sent messages with the phone number we had set.

“Bingo :),” the researcher said.

Revealing the private recovery phone number can even expose Google Anonymous Accounts to targeted attacks, such as redemption attempts. Identifying a private phone number associated with one’s Google account could make it easier for the specialized hackers to take control of this phone number through an SIM exchange attack, for example. By checking this phone number, the intruder may reset the password of any account associated with this phone number by creating password reset codes sent on this phone.

Given the potential danger to the general public, TechCrunch has agreed to keep this story until the error was corrected.

“This issue has always been determined the importance of cooperation with the Security Research Community through the susceptibility reward program and we would like to thank the researcher for signaling this issue,” Google Kimberly Samra spokesman said in Techcrunch. “Submissions of researchers like this are one of the many ways we can find quickly and correct issues for the safety of our users.”

Samra said the company has seen “not confirmed, direct links to exploit at the moment”.

Brutecat said Google paid $ 5,000 in a reward for the finding.

https://www.youtube.com/watch?v=am3iplyz4sw

cyberspace error fixes Google Numbers phone private reveal security defect Users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe Proxima Fusion joins the club of well -funded nuclear candidates in a series of € 130 million.
Next Article Uptime Industries wants to enhance the topical AI use with a “ai-in-a-box” called Lemony AI
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Crunchyroll confirms data breach after hackers claim unauthorized access

24 March 2026

Delve halts demos, Insight Partners sheds investment position amid ‘false compliance’ claims

24 March 2026

The FBI says Iranian hackers are using Telegram to steal data in malware attacks

23 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Crunchyroll confirms data breach after hackers claim unauthorized access

24 March 2026

Insight Partners removes investment post for Delve amid ‘false compliance’ claims.

24 March 2026

Zoox is bringing its robotaxis to Austin and Miami

24 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

23 March 2026

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026

Nominations for the Startup Battlefield 200 are still open

19 March 2026
Startups

Insight Partners removes investment post for Delve amid ‘false compliance’ claims.

Bengaluru food delivery startup Swish raises $38 million, its third round in 18 months

Cursor admits that his new coding model was built on top of Moonshot AI’s Kimi

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.