UPDATED 21:56 EST / MARCH 09 2021

SECURITY

Vulnerability in iPhone app exposed recorded phone calls

A vulnerability in an iOS call recording app was found to give access to recorded phone calls by knowing the phone number of a user.

Detailed today by Anand Prakash from PingSafe AI, the vulnerability was discovered in an app known as “Automatic Call Recorder” that had been downloaded more than a million times from the Apple App Store. As its name suggests, the app records incoming and outgoing phone calls automatically.

The vulnerability related to insecure communications going in and out of the app. Using a proxy tool such as Burp Suite, Prakash could view and modify network traffic, allowing him to pass another user’s number in the recording request. The application programming interface would then respond with the URL of the Amazon Web Services Inc. S3 storage bucket where the recording was being stored.

The company behind Automatic Call Recorder was informed of the vulnerability and a new version of the app went live on the App Store March 6. Any users who do not automatically have their apps updated are advised to install the update as soon as possible.

“Security issues like this are catastrophic in nature,” Prakash said. “Along with impacting customer’s privacy, these also dents the company’s image and provides added advantage to the competitors.”

Anurag Kahol, chief technology officer at cloud access security broker Bitglass Inc., told SiliconANGLE that anyone could have easily accessed the thousands of call recordings during the timeframe of exposure simply by knowing a user’s phone number.

“This was not only a violation of data privacy but also put the affected users at physical and cyber risk if their recorded conversations contained sensitive, personal details,” he said. “App makers that fail to invest in their own cybersecurity readiness must recognize that the fines they could face for non-compliance with data privacy laws are incredibly expensive – not to mention the cost of losing their customers’ trust.”

Image: Automatic Call Recorder

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.