OnePlus was reportedly leaking email id of users who uploaded images on the Shot on OnePlus app.
The company has taken note and is said to be patching the API that was leaking the info.
Apple iPhone XR 64GB at Lowest Price Ever
6.1" display | 50% Faster Graphics performance | TrueDepth camera
Click here to know more
Update June 18, 2019: OnePlus has updated the Shot on OnePlus experience to fix the problem. In an emailed statement, the company said, "OnePlus takes security seriously, and has updated the ShotOnOnePlus experience."
If you use a OnePlus smartphone might have noticed a ‘Shot on OnePlus’ application, which can be accessed via the wallpaper selection menu. The feature enables OnePlus users to set images as wallpapers that were captured via OnePlus phones, and a new wallpaper is added to it every day. 9to5Google has reported discovering a major bug in the option that is leaking email id of users online. OnePlus is said to use an API to facilitate connectivity between its server and the Shot on OnePlus app. This API is hosted on open.oneplus.net and is reportedly insecure as it can be accessed by anyone who has an access token. This access token can apparently be retrieved via an unencrypted key and the token and the key is said to be alphanumeric codes.
The API is used to fetch public images uploaded by users but as per a screenshot of it in action, it also displays their sensitive information like email id, upload location and time. The main issue arises due to a ‘gid’ used by the API to identify a user. Every user has a unique gid assigned to them and it can be used by OnePlus’s API to find and/or delete photos uploaded by a particular user. It can also be used to get information on a user like their email id, name and country. Since this id uses a unique number, one can cycle through the numbers to find other users.
OnePlus was informed about the flaw and the company made some changes to the API to plug the gid leak. “OnePlus takes security seriously, and we investigate all reports we receive,” OnePlus said in a statement. The API is no longer displaying email id of users whose images are publicly posted and currently, the company seems to be working on fixing it as trying to access information is said to be blocked.
Digit caters to the largest community of tech buyers, users and enthusiasts in India. The all new Digit in continues the legacy of Thinkdigit.com as one of the largest portals in India committed to technology users and buyers. Digit is also one of the most trusted names when it comes to technology reviews and buying advice and is home to the Digit Test Lab, India's most proficient center for testing and reviewing technology products.
We are about leadership-the 9.9 kind! Building a leading media company out of India.And,grooming new leaders for this promising industry.