Security flaw in Airtel app exposes customers data, according to independent researcher

A spokesperson acknowledged the flaw and said that it had been fixed after the company was alerted about it

Updated - December 08, 2019 01:16 am IST

Published - December 08, 2019 01:14 am IST - New Delhi

Representational image. File

Representational image. File

An independent cyber security researcher found technical flaws in an application of Bharti Airtel that exposed “sensitive user information” which the company claims to have fixed now.

According to the cyber security researcher Ehraz Ahmed the flaw existed in one of the Airtel app that allows “to fetch sensitive user information of any Airtel subscriber.”

“It revealed information like first and last name, gender, email, date of birth, address, subscription information, device capability information for 4G, 3G & GPRS, network information, activation date, user type (prepaid or postpaid) And current IMEI number,” Mr. Ahmed said in his blog. The IMEI number is a unique number that can be used to identify the device of the user.

“Every user that is on India’s Airtel network was at risk of getting their information leaked through this vulnerability, and risking over 325.5 million subscribers in India,” the researcher’s post said.

When contacted Bharti Airtel spokesperson acknowledged the flaw and said that it has been fixed as soon as the company was alerted about it.

“There was a technical issue in one of our testing APIs, which was addressed as soon as it was brought to our notice. Airtel’s digital platforms are highly secure. Customer privacy is of paramount importance to us and we deploy the best of solutions to ensure the security of our digital platforms,” an Airtel spokesperson said.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.