HomeSecurityApps with over 3 million installs leak Algolia API keys

Apps with over 3 million installs leak Algolia API keys

Of the 1,550 mobile apps studied, researchers found that many of them leaked Algolia API keys, risking the exposure of sensitive internal services and stored user information.

See also: Cyberattacks: A daily occurrence for modern businesses

Apps with over 3 million installs leak Algolia API keys
Apps with over 3 million installs leak Algolia API keys

Of these apps, 32 expose administrator secrets – meaning there are 57 different ways for an attacker to gain access to sensitive user information or modify app index files and settings.

CloudSEK, a Singapore-based cybersecurity firm, discovered this report and shared its findings exclusively with BleepingComputer.

See also: Mustang Panda: Uses Google Drive to drop malware on govt networks

Algolia API details

The Algolia API (Application Program Interface) is a platform used by over 11,000 companies to integrate search engines with discovery and recommendation features into websites and applications.

The system consists of five API keys for: Admin, Search, Monitoring, Usage and Analytics.

The Search key is the only one that needs to be public and accessible from the front-end code so that users can search for things within the application.

The Monitoring key allows administrators to check the status of their cluster, the Usage and Analytics keys provide usage statistics, and the Admin key offers access to four other API services.

Abuse of the above services may expose data containing user device and network access details, usage statistics, search logs, and handling of related information.

Disclosure of application IDs and API keys

CloudSEK scanners discovered that 1,550 applications share the Algolia API key and application ID, which could lead to unauthorized access to internal information.

The 32 apps leaking Admin API keys pose a critical security risk, exposing their users to the possibility of data leakage and malicious modifications that could cause damage to their businesses.

Algolia API administrator keys were exposed by multiple applications, some of which had over a million downloads.

Shopping apps were the most likely category with exposed keys, with a total of 2.3 million downloads – total app downloads are around 3,250,000

Algolia API apps

The category most prone to exposed keys was shopping apps, which were downloaded a total of 2.3 million times.

See also: Windows zero day exploit to drop Qbot software

CloudSEK has attempted to notify all application developers about the report, but has yet to receive a response from any of them.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS