HT TECH wants to start sending you push notifications. Click allow to subscribe

Security firm finds ‘thousands’ of mobile apps leaking personal information due to unsecured cloud configurations

According to Zimperium's analysis, 14 percent of apps using cloud storage had unsecure configurations and were vulnerable. 

By: HT TECH
Updated on: Mar 04 2021, 23:56 IST
These security flaws affect both iOS and Android, according to Zimperium. (Pixabay)

Security firm Zimperium has released a report that states there are unsecured cloud configurations currently exposing millions of peoples information in thousands of mobile apps on both iOS and Android, according to a report.

Developing apps for Android and iOS involves not only working on the user facing side of the interface but also the parts that interact with the web and the servers that host the content powering those apps. Apps also talk to cloud-based databases (such as Google’s Firebase) which means that developers don’t have to worry about complex APIs for things like notifications.

You may be interested in

7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details

Read more: Chinese hackers target Indian vaccine makers SII, Bharat Biotech, says security firm

“However, the process of securing these cloud containers used by mobile applications tends to be overlooked by app developers while the impact of a misconfigured cloud container on the app developer, their business and their users can be extremely high,” the company stated in a blog post.

The company’s zLabs Team found that 14 percent of the mobile apps studied that use cloud storage had set up insecure configurations and as a result exposed personally identifiable information or PII, enabled fraud and exposed intellectual property or systems and configurations.

Among the apps exposing PII were medical apps that revealed personal medical information including test results, and social media apps that exposed photos, phone numbers. Meanwhile, major game apps were found to expose server configuration, while fitness apps revealed the developer’s server app, allowing potential reverse engineering or manipulation of the apps, the company said in its blog post.

Also read: Google’s Gmail, others iOS apps updated for the first time since Apple’s privacy label enforcement

On the other hand the zLabs team also found a fortune 500 mobile wallet, a major city transportation app, a major online retailer, and a gambilng app all enabling fraud. Meanwhile, a major music app, a major news service a fortune 500 software company, major airport, major hardware developer and an asian government travel app could be putting intellectual property at risk. The company has not yet named the apps in the report as many of the security vulnerabilities still exist, according to a report by Wired.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 04 Mar, 23:53 IST

Sale

4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,590₹89,900
Buy now
NEXT ARTICLE BEGINS