A bug in Truecaller’s Guardian app could let hackers track user’s family
By MYBRANDBOOK
Truecaller has launched its Guardian app that has been designed to share location and important details with ‘guardians’ of user’s choice in cases of emergency. The app is supposed to be able to get users aid as quickly as possible at the location users are in. Soon after the app was announced, a major bug was discovered that could let hackers take full control over users’ accounts and track them.
According to a report, security researcher Anand Prakash discovered a vulnerability in the Guardian app and informed Truecaller about it. It was fixed on the same day.
The bug discovered by Prakash was in the app’s “Log in with Truecaller API”. This meant that a hacker could use user’s phone number to log into their account on the Guardian app. They could then intercept the API’s request and change the phone number to get access to user’s account and control it.
This account takeover could let hackers add themselves or pretty much anyone else as a trusted contact on another person’s profile. This bug also allowed the hacker to view your family members’ details like name, birth dates, phone number and live location.
Truecaller said in a statement that that the bug was a development configuration that made its way to the final roll by mistake.
“In this case, the issue pointed out by Anand was due to a development configuration being rolled out by mistake during the launch phase. Our engineers were already rolling out a fix at the time of his submission to ensure user safety,” Truecaller said.
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
Icons Of India : Anil Agarwal
Anil Agarwal, the Founder and Chairman of Vedanta Resources Ltd., is r...
Icons Of India : PRATIVA MOHAPATRA
Prativa is a transformational leader with an incredible breadth of exp...
Icons Of India : AMIT CHADHA
Amit Chadha serves as the CEO and Managing Director of L&T Technology ...
IOCL - Indian Oil Corporation Ltd.
IOCL is India’s largest oil refining and marketing company ...
UIDAI - Unique Identification Authority of India
UIDAI and the Aadhaar system represent a significant milestone in Indi...
GeM - Government e Marketplace
GeM is to facilitate the procurement of goods and services by various ...
Indian Tech Talent Excelling The Tech World - Steve Sanghi, Executive Chair, Microchip
Steve Sanghi, the Executive Chair of Microchip Technology, has been a ...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...