Major security vulnerability! It has been revealed that phone numbers on Google can be accessed in minutes
A security vulnerability has been identified and quickly patched that allowed phone numbers linked to Google accounts to be compromised in seconds.
12punto
A Singaporean security researcher discovered that phone numbers linked to Google accounts could be easily guessed using brute-force methods. The vulnerability was reported to Google on April 14, 2025, and according to the researcher's findings, Singaporean numbers could be cracked in an average of 5 seconds, while US numbers could be solved in approximately 20 minutes.
The security flaw was found on a deprecated JavaScript-disabled username recovery page. This page lacked basic security measures such as CAPTCHA and could be easily exploited by attackers. The last two digits of the number shown on Google's password reset screen also facilitated the attack.
The researcher developed a three-stage method to exploit this vulnerability. First, the target user's name was identified using Google Looker Studio, then the last two digits of the number were obtained via the password reset screen, and finally, the full number was guessed by making systematic attempts through the recovery page.
Google acted quickly to close this security vulnerability and completely disabled the relevant recovery page on June 6, 2025. The researcher was awarded 5,000 dollars for this significant discovery. This incident follows the same researcher's previous disclosure of another vulnerability that could expose the account information of YouTube content creators.