A security flaw found in a popular iPhone call recording app exposes thousands of users' recorded conversations. The flaw was discovered by Anand Prakash, a security researcher and founder of PingSafe AI, who found that the Call Recorder allows anyone to access other users' call recordings. All someone needs to do is know a user's phone number.
Additionally, by using a readily available proxy tool like Burp Suite, Prakash could view and modify the network coming in and out of the app. This means he could replace his phone number registered in the app with the phone number of another app and access the recordings he made on his phone.

TechCrunch verified Prakash's findings using a backup phone with a dedicated account.
The app stores a user's call logs in a cloud storage bucket hosted on Amazon Web Services. Although the cloud storage server was open and listed the files inside, the files could not be accessed or downloaded.
The cloud storage bucket currently has more than 130,000 recordings, totaling about 300 gigabytes. The iPhone app says it has had more than 1 million downloads so far.

As TechCrunch reports, it contacted the app developer and kept the security issue under wraps until the flaw was fixed. A new version of the app was submitted to Apple ’s App Store on March 6. According to reports, the app update was intended to “fix a security issue.”
Despite a brief response to TechCrunch's initial email acknowledging the security flaw, the app's developer, Arun Nair, declined to comment on the matter.
