Swarajya Logo

Insta

Airtel’s Mobile Application Flaw Risks Sensitive And Personal Information Of 32 Crore Mobile Subscribers

IANSDec 08, 2019, 08:38 AM | Updated 08:38 AM IST
Bharti Airtel (Representative image) (INDRANIL MUKHERJEE/AFP/Getty Images)

Bharti Airtel (Representative image) (INDRANIL MUKHERJEE/AFP/Getty Images)


Data of over 32 crore subscribers of telecom major Airtel were exposed and became vulnerable due to a serious security flaw in its mobile application.

Ehraz Ahmed, a Bengaluru-based researcher, who first noticed the fault, said in his blog written on Friday (7 December) that the flaw existed in one of Airtel's API (Application Program Interface) that allowed people to fetch sensitive user information of any Airtel subscriber.

According to reports, Airtel confirmed the breach saying that it has fixed the security flaw associated with its application. Ahmed also posted a video, which shows a script being used to fetch the information from the Airtel mobile app's API.


The IMEI number can be used to identify the device of an user. According to the blog, every user on Airtel network was at the risk of getting his/her information leaked through this vulnerability.

Airtel is the third largest telecom service provider in the country in terms of subscribers after Vodafone-Idea and Reliance Jio.

(This story has been published from a wire agency feed without modifications to the text. Only the headline has been changed.)

Join our WhatsApp channel - no spam, only sharp analysis