TikTok Alternative Mitron App Has A Critical Vulnerability Allowing Account Takeovers2 juin 2020
The latest social media craze Mitron app has a critical vulnerability. As discovered, the bug allows an adversary to takeover TikTok Alternative Mitron App Has A Critical Vulnerability Allowing Account Takeovers on Latest Hacking News .
Mitron App Vulnerability Discovered Security researcher Rahul Kankrale has discovered a critical and easily exploitable vulnerability in the Mitron app. Sharing the details the researcher revealed that the problem exists with the ‘Login with Google’ feature. Briefly, the feature that requires users’ permission to access profile information does not create any private authentication tokens. Hence, anyone knowing a target users’ unique userID (publicly displayed in the page source) can easily take over the account. The researcher has shared the quick steps to reproduce the exploit in his blog post. Whereas, the following video demonstrates the attack scenario.