Loading HuntDB...

Password and mail address stored unencrypted in memory - Rockstar Game Launcher

Medium
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report, the researcher discovered that user credentials were, during the login process, briefly being stored in plaintext in memory for the Rockstar Games Launcher application. Exploitation would have required an attacker to have user-level access to the device in question. The credentials could be retrieved by dumping the application's memory shortly after login. This issue has been resolved, and the user's password is no longer exposed in application memory.

Reported by mbit

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$750.00

Submitted

Weakness

Missing Encryption of Sensitive Data