Security researcher BruteCat has unveiled a critical vulnerability in Google's user account recovery system. This flaw enables the retrieval of complete phone numbers by leveraging the target's display name and partial phone number information. The exploit takes advantage of an outdated username recovery form, coupled with IPv6 address rotation techniques and CAPTCHA circumvention methods. BruteCat's developed tool, dubbed "gpb," efficiently cracks phone numbers across multiple countries. Although Google deprecated the affected endpoint on June 6th, it remains uncertain whether the vulnerability was maliciously exploited prior to its patching.