Уровень 0 · материалов: 3
В кластер входят документы об эксплойтах, позволяющих получить доступ к конфиденциальным данным пользователей (номерам телефонов, адресам, кодам восстановления), и не входят документы об общих сбоях системы без утечки данных.
Общие признаки: утечка личной информации, ошибки в API и сессиях, раскрытие номеров телефонов и адресов, поиск данных пользователей
Группа выше: Утечки через ошибки доступа и предсказуемые идентификаторы
Смысл: The text explains a technical security flaw in Google's account recovery system that permitted an attacker to reveal a user's full phone number by combining an outdated non-JS endpoint, a token bypass, and a data leak from Looker Studio.
A security researcher discovered and reported a vulnerability in Google's recovery forms that allowed bruteforcing user phone numbers by bypassing BotGuard protections and using Looker Studio for name discovery.
Смысл: The text details a successful bug bounty discovery where a flaw in session management allowed an attacker to obtain a victim's account recovery code by linking two different phone numbers to a single session ID.
A security researcher discovered a vulnerability in VK and ICQ that allowed account hijacking by sending the same recovery code to two different phone numbers using a shared session ID.
Смысл: The text exposes a severe privacy leak in a telecom provider's mobile app where sensitive user addresses could be retrieved using only an email or phone number due to a flawed API design.
A security researcher discovered that InterZet/DomRU's iOS app leaked users' exact home addresses via an insecure password recovery API endpoint.