Bug hits Truecaller app threatening the security of millions of users
By MYBRANDBOOK
A serious vulnerability was discovered in the popular call-blocking application Truecaller that could have threatened the security of millions of users.
It was found out by Indian security researcher Ehraz Ahmed. According to the discovery, the vulnerability allowed a user to plant a URL into the profile picture. Hence, a potential attacker could exploit the flaw to inject a malicious URL to the profile picture. As a result, anyone clicking on the profile would fall victim to the attack.
The researcher further revealed that such attacks could allow the attacker to extract numerous details about the user. This includes fetching the victim’s IP address, user-agent and time without them knowing.
He has also shared a POC of the exploit demonstrating how an attacker could fetch victim’s information.
After having discovered the bug, Truecaller was informed about the matter before going public. Consequently, Truecaller patched the flaw in the app’s API and has released the fix.
“It was recently brought to our attention that there was a small bug in our app services which allowed the modification of one’s own profile in an unintended way. We thank the security researcher for bringing this to our notice and collaborating with us. The bug was immediately fixed. Since it’s a critical bug affecting all Truecaller applications, users must ensure they update their devices with the latest patched versions,” said Truecaller in one of its statements.
Truecaller has also disclosed its plans to announce a bug bounty program soon.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
DATA SAFEGUARD INDIA PRIVATE LIMITED
BPE INDIA PVT. LTD.
STERLITE TECHNOLOGIES LTD.
GLOBUS INFOCOM LTD.
Icons Of India : Dilip Asbe
At present, Dilip Asbe is heading National Payments Corporation of Ind...
ICONS OF INDIA : SANJAY GUPTA
Sanjay Gupta is the Country Head and Vice President of Google India an...
Icons Of India : NEERAJ MITTAL
He started his career as an IAS Officer in 1992. He has held various a...
HPCL - Hindustan Petroleum Corporation Ltd.
HPCL is an integrated oil and gas company involved in refining, market...
NSE - National Stock Exchange
NSE is the leading stock exchange in India....
RailTel Corporation of India Limited
RailTel is a leading telecommunications infrastructure provider in Ind...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - REVATHI ADVAITHI, CEO- Flex
Revathi Advaithi, the CEO of Flex, is a dynamic leader driving growth ...
Indian Tech Talent Excelling The Tech World - AJAY BANGA, President - World Bank
Ajay Banga is an Indian-born American business executive who currently...