menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

3d

read

59

img
dot

Image Credit: Securityaffairs

A flaw could allow recovery of the phone number associated with any Google account

  • A vulnerability was discovered that could potentially allow for the recovery of the phone number associated with any Google account through a brute force attack.
  • The flaw was found in a deprecated, JavaScript-disabled version of Google's username recovery page that lacked anti-abuse protections.
  • By bypassing CAPTCHA rate limits and using BotGuard tokens, an attacker could rapidly test combinations of a user's phone number, revealing recovery details linked to a Google account display name.
  • After reporting the issue to the vendor, a reward was given to the security researcher, and mitigations were rolled out to address the vulnerability.

Read Full Article

like

3 Likes

For uninterrupted reading, download the app