Medium
resolved
resolved
Adding phone number to profile By OTP brute forcing
Bug reported by Ganesh Reddy was disclosed at August 8, 2026, 9:11 am | Insecure Storage of Sensitive Information
A vulnerability was found that allowed an attacker to add any phone number to a user's profile by brute-forcing the one-time password (OTP) used for phone number verification. The steps involved intercepting the OTP verification request, using a brute-force attack to find the valid OTP, and then replaying the original request with the discovered OTP to complete the phone number addition.

