Google has only partially mitigated the attack, which involves using a malicious Android app to secretly discern the two-factor codes generated by authenticator apps.
You can transfer contacts from an Android phone to another Android by syncing them to a Google account, or by sending a vCard ...