
Security researchers from Cheetah Mobile have discovered a privacy flaw in Truecaller â the worldâs largest caller ID app â that puts the personal information of over a hundred million users in danger.
As Cheetah Mobile explains in its report, Truecaller uses a devicesâ IMEI number to assign identities to its users, which means that anyone with access to a deviceâs IMEI could tamper with your personal information without explicit consent.
By exploiting this defect, attackers can steal and alter details such as âaccount name, gender, e-mail, profile pic, home addressâ. Additionally, hackers can also modify application settings, disable spam blockers and edit (or delete) usersâ blacklists.
Truecaller has since quickly flagged and fixed the bug, but users still need to update to the appâs latest iteration â that was released on March 22 â in order to ensure the safety of their private details.
According to Truecallerâs statement, monitoring analysis indicates that so far âno user information has been compromisedâ as a result of this vulnerability.
Get the TNW newsletter
Get the most important tech news in your inbox each week.