A popular Google Play app, Camera360 Ultimate, has been found to be inadvertently leaking sensitive data. This gives malicious parties unauthorized access to users' Camera360 Cloud accounts and photos.

FireEye, which previously discovered SSL man-in-the-middle vulnerabilities in the widely used Camera360 app and many other popular apps, has revealed the vulnerability. Camera360 is a popular photo-taking and editing app with millions of users worldwide. It also offers a free cloud service for storing images – to use the cloud option, users create a cloud account that they can also log in to via the website www.cloud.camera360.com. That’s where the problem lies.
Access to the cloud is protected by a username and password. But when the app enters the cloud, it leaks sensitive data, in unencrypted form, with the Android system log (logcat) and with network traffic.
Apps that can read the logcat or perceive network traffic can intercept this data. At the same time, a malicious party appearing on the same Wi-Fi network as the device could steal this data using Wi-Fi sniffing.
“The leaked data could be used to download all of the user’s photos, except those in the user’s secret album,” FireEye explained. “The secret album option uses an additional password to secure important images. The specific Android app does not have access to these secret images, and all images uploaded from the device to the cloud are by default non-secret.”
“It is vital that Android app developers improve security to provide users with a better and more protected Android experience,” FireEye concluded.
