Loading HuntDB...

Connection informaton is sent to a third-party service

Critical
N
Nord Security
Submitted None

Team Summary

Official summary from Nord Security

Application event data exposed through the reuse of API key The researcher reported that iOS app usage event information sent to the third party service can be intercepted through the reuse of API key. In order to resolve the issue we have disabled GET requests for API keys, removed the third party SDK and per DPA terms deleted all event data that has ever been sent.

Reported by martinbydefault

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privacy Violation