HomeSecurityOnePlus devices: Critical application bug exposes users' emails!

OnePlus devices: Critical application bug exposes users' emails!

A critical security flaw in the wallpaper app Shot on for OnePlus devices is leaking email users' API addresses . The flaw lies in the that hosts the photos.

Shot on OnePlus is an application used to access photos uploaded by OnePlus, allowing them to set wallpaper and upload photos from the app or via the web.

9to5Google reported the bug in the API that facilitates connectivity between the server and the OnePlus app. The API , hosted on open.oneplus.net, is insecure and accessible to anyone with the access ID.

 

The API is primarily used to download public photos, but it manages to expose sensitive data that shouldn't be public.

OnePlus devices: Critical application bug exposes users' emails!

Specifically, it exposes the detailed information of the photo, including the photo ID, author, email, photo subject, location uploaded, and upload time. It's unclear how long the bug in the app. 9to5Google believes the bug has been around since the app was released.

Another critical vulnerability is the OnePlus GID, which is used to identify the user. The GID is an alphanumeric code used by the OnePlus API to find photos added by the user.

The first part of the gid represents that “the user is from China (CN) or somewhere else (EN)” and the second part is the “unique number, like 123456”, which can be easily discovered by someone typing random numbers.

9to5Google reached out to OnePlus about the issue but did not receive an immediate response. OnePlus has made changes to the API as well as the GID.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS