Connection informaton is sent to a third-party service
Critical
N
Nord Security
Submitted None
Team Summary
Official summary from Nord Security
Application event data exposed through the reuse of API key The researcher reported that iOS app usage event information sent to the third party service can be intercepted through the reuse of API key. In order to resolve the issue we have disabled GET requests for API keys, removed the third party SDK and per DPA terms deleted all event data that has ever been sent.
Actions:
Reported by
martinbydefault
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privacy Violation