OnePlus discloses security leak in its invoicing system that could have exposed sensitive user data

OnePlus discloses security leak in its invoicing system that could have exposed sensitive user data

SHARE:

While the company gears up to launch the OnePlus Nord, a security vulnerability has been found that could have led to leaking user data. Tha...

Vivo Y91i with MediaTek Helio P22 SoC, 4030mAh battery launched in India at Rs 7990
Xiaomis next flagship phone might be more expensive than before, hints Lei Jun
Samsung Galaxy A90, Galaxy A40 and Galaxy A20e listed on official UK website

While the company gears up to launch the OnePlus Nord, a security vulnerability has been found that could have led to leaking user data. Thanfully, the vulnerability involves only a small set of users, and OnePlus claims the leakage has not been exploited by anybody malicious.

First reported by Android Police, the vulnerability was found in one of OnePlus’ out-of-warranty repair invoicing systems, affecting a small set of users in the US. The invoicing system was run by a third party. The publication notified OnePlus and worked together to iron out the issue.

If the vulnerability was exploited, they would have been able to see data of users who wanted to repair their OnePlus device that had gone out of warranty, and hence had to pay for it. Via the invoice, someone could have had access to data like phone number, model number, IMEI, order date, name, address, email address and the repair cost. OnePlus maintained that credit card details were never exposed.

After fixing the leak, OnePlus gave out a detailed statement to Android Police, which read:

“On July 2, a vulnerability was fixed on the website of our U.S. repair service provider. OnePlus customers in the U.S. who were required to pay for out-of-warranty repairs or those who chose to use our recently launched warranty exchange program were sent a unique third-party link to process their payment. From the time the payment link was generated and emailed to the customer, until the time the payment information was submitted, that customer's name, shipping address, email address, device model and IMEI were visible at the link. As soon as a user's payment information was submitted, the link immediately became inactive. To further secure this process, an additional verification step will be required starting early next week.

After thorough investigation together with our vendor, we have found no evidence of any purposeful attempts to access these URLs.

In addition, no credit card details or payment information of any kind was ever accessible.

User privacy is a top priority for OnePlus, and we apologize for any concerns that this might cause. We have made significant security enhancements on our own platforms in recent years and are diligently working to further improve. We are also already improving our internal processes to more quickly respond to external vulnerabilities, and will more closely engage our third-party vendors to better ensure security on their platforms.”

It’s worth mentioning that the vulnerability affects only a small set of users, and was quickly fixed by OnePlus who claims it didn’t fall into wrong hands for the time it was left exposed. OnePlus was also embroiled in a data leak controversy in 2018 and 2019, which actually saw user data being accessed by malicious third parties. For now, OnePlus has introduced a new verification step in the invoicing process and scrubbed all identity details from invoices.



from Latest Technology News https://ift.tt/2BDL2fR
Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: OnePlus discloses security leak in its invoicing system that could have exposed sensitive user data
OnePlus discloses security leak in its invoicing system that could have exposed sensitive user data
http://feeds.feedburner.com/~r/digit/latest-news/~4/ZyOFQpQQyVE
Genius Baba
https://geniusbabaa.blogspot.com/2020/07/oneplus-discloses-security-leak-in-its.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2020/07/oneplus-discloses-security-leak-in-its.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy