HT TECH wants to start sending you push notifications. Click allow to subscribe

Chingari responds to being called ‘easily hackable’, shares app updates with security patch

An ethical hacker showed how easily Chingari could be hacked and anyone could get access and take over any user's account irrespective of the device and the OS. 

By: HT TECH
Updated on: Aug 20 2022, 21:49 IST
Chingari has a vulnerability that allows it to be easily exploited and anyone can hijack any user account on any smartphone and ‘tamper’ with user information, content and even upload videos. (HT Tech)
Chingari has a vulnerability that allows it to be easily exploited and anyone can hijack any user account on any smartphone and ‘tamper’ with user information, content and even upload videos. (HT Tech)

Chingari, the TikTok clone that suddenly got very popular across the country thanks to TikTok getting banned by the Indian government, is allegedly really easy to hack. The app has a vulnerability that allows it to be easily exploited and anyone can hijack any user account on any smartphone and ‘tamper’ with user information, content and even upload videos.

This report comes courtesy The Hacker News (THN) that shared a video showing exactly how easily this could be done. New users can register an account on the Chingari app on both iOS and Android by granting the app a basic profile access to their Google accounts, the report states.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

While many other apps also do this, Girish Kumar, a cybersecurity researcher at Encode Middle East firm in Dubai, told THN that Chingari uses a randomly generated user ID to fetch profile information of the user along with other data from the server without relying on a secret token for user authentication and authorisation.

Kumar shared a video that shows how easily the user ID can be retrieved and be replaced by a hacker in HTTP requests to gain access to account information. He also told THN that once the victim’s account is compromised, the attacker can change any and all information and also upload videos - essentially, the hacker gets full access to the account.

Besides this, Chingari also has another feature that allows users to turn off video sharing and comments and this can be bypassed by changing the HTTP response code allowing pretty much anyone to share and comment on restricted videos.

Kumar informed Chingari about these issues and the company has responded today with a security patch -

“There was a security issue in Chingari (V 2.4.0 and below). The issue was notified to us 24 hours ago has been addressed and patched already by the team. We have pushed updates both on Play Store & App Store with fixes. The old app may not work as we have shut down the vulnerable APIs. It is advisable to update the app to the latest version. Rest assured your sensitive data like email etc are not compromised. No user data was compromised due to this vulnerability,” the company said in a statement today.

Version 2.4.1 for Android and 2.2.6 for iOS comes with the security fix and if you are using Chingari we suggest you update your app immediately.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 11 Jul, 19:45 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
36% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹18,699₹28,999
Buy now
31% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,990₹14,500
Buy now
15% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹96,421₹113,798
Buy now
37% OFF
Wishtel IRA T811
  • 4 GB RAM
  • 64 GB Storage
₹11,999₹18,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
27% OFF
Asus ROG Strix G15 G513QM HF318TS Laptop
  • Eclipse Grey
  • 16 GB RAM
  • 1 TB SSD
₹84,990₹115,990
Buy now
39% OFF
Asus TUF Gaming F15 FX506HF HN026W Laptop
  • Black
  • 8 GB RAM
  • 1 TB SSD
₹55,600₹90,990
Buy now
23% OFF
Asus ROG Strix SCAR II GL504GV ES019T Laptop
  • Gun Metal
  • 16 GB RAM
  • 1 TB HDD
₹199,990₹259,990
Buy now
NEXT ARTICLE BEGINS