The app GroupMe was recently updated to fix a bug that allowed a third party to log into other accounts knowing only the device owner's number.
The application, although owned by Microsoft, is available for all computer and mobile operating systems (iOS and Android), with the Android version having been installed over 5 million times. The bug was found by security researcher Dylan Saccomanni, in New York, who discovered that the script that confirms the identity of the device owner could be “broken” with a brute-force attack. Therefore, anyone could enter any mobile phone number and log into a GroupMe account.
Unlike other apps, GroupMe is linked to a phone number rather than an email address, and the user can register with either their device number or another mobile phone number. The app then sends a four-digit verification number to the number used to register for the service.
The problem was especially in the iOS version where the app wouldn't lock after incorrect attempts, allowing someone to brute-force the number and get into the app. There are only 10,000 different combinations for four-digit numbers.
The bug was fixed in 20 days.
The patch to fix this bug was released about 20 days after its discovery, relatively quickly, since there was a great risk to users' personal data. Even the email and password could be changed by someone who hacked into the account.
The issue was specifically identified in iOS version 4.4.4 and earlier and was fixed in version 5.0 and later.

