Password and mail address stored unencrypted in memory - Rockstar Game Launcher
Medium
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
In this report, the researcher discovered that user credentials were, during the login process, briefly being stored in plaintext in memory for the Rockstar Games Launcher application. Exploitation would have required an attacker to have user-level access to the device in question. The credentials could be retrieved by dumping the application's memory shortly after login. This issue has been resolved, and the user's password is no longer exposed in application memory.
Actions:
Reported by
mbit
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$750.00
Submitted
Weakness
Missing Encryption of Sensitive Data