Bug hits Truecaller app threatening the security of millions of users
By MYBRANDBOOK
A serious vulnerability was discovered in the popular call-blocking application Truecaller that could have threatened the security of millions of users.
It was found out by Indian security researcher Ehraz Ahmed. According to the discovery, the vulnerability allowed a user to plant a URL into the profile picture. Hence, a potential attacker could exploit the flaw to inject a malicious URL to the profile picture. As a result, anyone clicking on the profile would fall victim to the attack.
The researcher further revealed that such attacks could allow the attacker to extract numerous details about the user. This includes fetching the victim’s IP address, user-agent and time without them knowing.
He has also shared a POC of the exploit demonstrating how an attacker could fetch victim’s information.
After having discovered the bug, Truecaller was informed about the matter before going public. Consequently, Truecaller patched the flaw in the app’s API and has released the fix.
“It was recently brought to our attention that there was a small bug in our app services which allowed the modification of one’s own profile in an unintended way. We thank the security researcher for bringing this to our notice and collaborating with us. The bug was immediately fixed. Since it’s a critical bug affecting all Truecaller applications, users must ensure they update their devices with the latest patched versions,” said Truecaller in one of its statements.
Truecaller has also disclosed its plans to announce a bug bounty program soon.
The government of India intends to construct a single portal f
A single portal will be launched by the Indian government to list all of it...
OpenAI offers GPT-4o, a faster model available to all users at
GPT-4o, a faster and more sophisticated AI model, is made available to all...
Paytm brings UPI Lite Wallet for low-value transactions
Paytm’s parent company One97 Communications (OCL) is emphasizing upon UP...
BHIM to join e-commerce, competing with PhonePe and Google Pay
The government-supported payment software BHIM is getting ready to join t...
JUVAS SOLUTIONS PVT. LTD.
FINOLEX INDUSTRIES LTD.
VERSA NETWORKS INDIA PVT. LTD.
BEETEL TELETECH LTD.
Technology Icons Of India 2023: Harsh Jain
Harsh Jain is an Indian Entrepreneur, the co-founder and CEO of the In...
Technology Icons Of India 2023: Nandan Nilekani
Nandan Nilekani is the Co-Founder and Chairman of the Board, Infosys T...
Technology Icons Of India 2023: Shailender Kumar
Shailender Kumar is senior vice president and regional managing direct...
ITI Limited widening its focus area
ITI Limited is a public sector undertaking company, has manufacturing ...
GeM maintains transparency in online procurement of goods & services
Created in a record time of five months, Government eMarketplace is a ...
Leading company into fertilizers in the country
NFL is a dynamic organization committed to serve the farming community...
INFLOW TECHNOLOGIES PVT. LTD.
Inflow Technologies is a niche player in the IT Infrastructure Distrib...
WPG C&C COMPUTERS & PERIPHERALS PVT. LTD.
WPG C&C Computers & Peripherals (India) was incorporated in 2008 and ...
TECHNOBIND SOLUTIONS PVT. LTD.
TechnoBind’s business model is focused on identifying and partnering...