A cybersecurity researcher was able to uncover phone numbers linked to Google accounts, which is typically private information.
The vulnerability that allowed this has been fixed, but it posed a significant privacy risk as even hackers with limited resources could access personal data.
The researcher, known as brutecat, used a process of brute forcing to reveal phone numbers, which can facilitate SIM swapping attacks.
Google has acknowledged and addressed the issue, emphasizing the importance of collaboration with the security research community.