Close Menu
    Trending
    • Minecraft Multiplayer – How To Play With Friends
    • Eriksholm: The Stolen Dream breaks cover to reveal a release date
    • Overwatch 2: 10 best Mercy skins in 2025: Top cosmetics for Angela Ziegler
    • Why Silicon Valley Needs Immigration
    • China Takes on Student Cheating by Shutting Off AI Nationwide During Exams
    • Apple opens its foundational AI models to developers
    • Best USB adapter for travel 2025
    • How to add a custom activity type to a Garmin watch
    Tech Trends Today
    • Home
    • Technology
    • Tech News
    • Gadgets & Tech
    • Gaming
    • Curated Tech Deals
    • More
      • Tech Updates
      • 5G Technology
      • Accessories
      • AI Technology
      • eSports
      • Mobile Devices
      • PC Gaming
      • Tech Analysis
      • Wearable Devices
    Tech Trends Today
    Home»Technology»A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
    Technology

    A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account

    GizmoHome CollectiveBy GizmoHome CollectiveJune 9, 202504 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    A cybersecurity researcher was ready to determine the cellphone quantity linked to any Google account, info that’s often not public and is usually delicate, based on the researcher, Google, and 404 Media’s personal checks.

    The difficulty has since been fastened however on the time introduced a privateness situation wherein even hackers with comparatively few sources might have brute compelled their technique to peoples’ private info.

    “I feel this exploit is fairly unhealthy because it’s principally a gold mine for SIM swappers,” the impartial safety researcher who discovered the difficulty, who goes by the deal with brutecat, wrote in an e-mail. SIM swappers are hackers who take over a target’s phone number so as to obtain their calls and texts, which in flip can allow them to break into all method of accounts.

    In mid-April, we supplied brutecat with one in all our private Gmail addresses so as to take a look at the vulnerability. About six hours later, brutecat replied with the proper and full cellphone quantity linked to that account.

    “Basically, it is bruting the quantity,” brutecat stated of their course of. Brute forcing is when a hacker quickly tries totally different mixtures of digits or characters till discovering those they’re after. Usually that’s within the context of discovering somebody’s password, however right here brutecat is doing one thing just like decide a Google person’s cellphone quantity.

    Brutecat stated in an e-mail the brute forcing takes round one hour for a U.S. quantity, or 8 minutes for a UK one. For different nations, it may take lower than a minute, they stated.

    In an accompanying video demonstrating the exploit, brutecat explains an attacker wants the goal’s Google show identify. They discover this by first transferring possession of a doc from Google’s Looker Studio product to the goal, the video says. They are saying they modified the doc’s identify to be thousands and thousands of characters, which finally ends up with the goal not being notified of the possession swap. Utilizing some customized code, which they detailed in their write up, brutecat then barrages Google with guesses of the cellphone quantity till getting a success.

    “The sufferer isn’t notified in any respect :)” a caption within the video reads.

    A Google spokesperson instructed 404 Media in an announcement “This situation has been fastened. We have all the time careworn the significance of working with the safety analysis neighborhood by means of our vulnerability rewards program and we wish to thank the researcher for flagging this situation. Researcher submissions like this are one of many some ways we’re capable of shortly discover and repair points for the protection of our customers.”

    Telephone numbers are a key piece of data for SIM swappers. These types of hackers have been linked to numerous hacks of particular person folks so as to steal online usernames or cryptocurrency. However subtle SIM swappers have additionally escalated to concentrating on huge corporations. Some have worked directly with ransomware gangs from Jap Europe.

    Armed with the cellphone quantity, a SIM swapper might then impersonate the sufferer and persuade their telecom to reroute textual content messages to a SIM card the hacker controls. From there, the hacker can request password reset textual content messages, or multi-factor authentication codes, and log into the sufferer’s invaluable accounts. This might embrace accounts that retailer cryptocurrency, or much more damaging, their e-mail, which in flip might grant entry to many different accounts.

    On its web site, the FBI recommends folks don’t publicly promote their cellphone quantity for that reason. “Defend your private and monetary info. Don’t promote your cellphone quantity, handle, or monetary property, together with possession or funding of cryptocurrency, on social media websites,” the site reads.

    Of their write-up, brutecat stated Google awarded them $5,000 and a few swag for his or her findings. Initially, Google marked the vulnerability as having a low likelihood of exploitation. The corporate later upgraded that chance to medium, based on brutecat’s write-up.



    Source link

    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    GizmoHome Collective

    Related Posts

    Why Silicon Valley Needs Immigration

    June 9, 2025

    Finally, I found the perfect wireless charger for all my Apple devices

    June 9, 2025

    Apple WWDC Live Blog: All the Updates, as They Happen

    June 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Best Buy Offers HP 14-Inch Chromebook for Almost Free for Memorial Day, Nowhere to be Found on Amazon

    May 22, 2025

    The Best Sleeping Pads For Campgrounds—Our Comfiest Picks (2025)

    May 22, 2025

    Time has a new look: HUAWEI WATCH 5 debuts with exclusive watch face campaign

    May 22, 2025
    Latest Posts
    Categories
    • 5G Technology
    • Accessories
    • AI Technology
    • eSports
    • Gadgets & Tech
    • Gaming
    • Mobile Devices
    • PC Gaming
    • Tech Analysis
    • Tech News
    • Tech Updates
    • Technology
    • Wearable Devices
    Most Popular

    Best Buy Offers HP 14-Inch Chromebook for Almost Free for Memorial Day, Nowhere to be Found on Amazon

    May 22, 2025

    The Best Sleeping Pads For Campgrounds—Our Comfiest Picks (2025)

    May 22, 2025

    Time has a new look: HUAWEI WATCH 5 debuts with exclusive watch face campaign

    May 22, 2025
    Our Picks

    This Bluetooth Label Maker Is Almost Free on Amazon, Already Bought by 20K People in the Past Month

    May 24, 2025

    The one thing your phone camera actually needs isn’t more megapixels

    June 6, 2025

    The Tetris Effect team is back with Lumines Arise

    June 4, 2025
    Categories
    • 5G Technology
    • Accessories
    • AI Technology
    • eSports
    • Gadgets & Tech
    • Gaming
    • Mobile Devices
    • PC Gaming
    • Tech Analysis
    • Tech News
    • Tech Updates
    • Technology
    • Wearable Devices
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    • Curated Tech Deals
    Copyright © 2025 Gizmohome.co All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.