Google fixed a bug that could reveal users' private recovery phone numbers.The bug was discovered by a security researcher and reported to Google in April.The bug exploit involved an 'attack chain' to obtain the recovery phone number of a Google account.Google confirmed fixing the bug and rewarded the researcher with a $5,000 bug bounty.