Security Flaw in Kari Kadai App Exposes User Auth Tokens Before OTP Verification

Security researcher Mughunthen from Neyveli discovered a critical authentication vulnerability in The Kari Kadai, a local food delivery app. The app's login API was returning sensitive authentication tokens in its initial response, before users completed OTP verification. This flaw allowed anyone with a target user's phone number to intercept the token and bypass two-factor authentication entirely. The vulnerability potentially exposed personal data including user profiles, order history, and saved addresses. Mughunthen has reported the issue to India's cybersecurity agency CERT-IN, and a fix is currently pending.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in