Mitron App, an Emerging TikTok Alternative, Said to Have Vulnerability That Puts User Accounts at Risk

Mitron app allows an attacker to gain access to a victim’s profile and send messages to other users.

Advertisement
By Jagmeet Singh | Updated: 30 May 2020 19:58 IST
Highlights
  • Mitron app allegedly allows attackers to take over user accounts
  • It uses unique user IDs to enable login
  • Mitron app developer is yet to fix the reported vulnerability

Mitron app already has over 50 lakh downloads on Google Play

Mitron app, which was launched as an alternative to TikTok and has gained notable popularity in a short time, allegedly has a vulnerability that could allow an attacker to compromise user accounts and send messages on behalf of a specific user. The flaw doesn't allow any bad actor to steal personal information such as the email ID that a user has used to sign up an account on the Mitron app. However, it can be exploited to gain access to the profile of the affected user. The Mitron app is so far exclusive to Android and has reached over 50 lakh downloads on Google Play.

By exploiting the vulnerability of the Mitron app, an attacker could send messages to other users and even follow other people or comment on behalf of the victim, cyber-security researcher Rahul Kankrale told Gadgets 360. He said the issue exists within the login process of the app that allows bad actors to intercept and gain the unique user ID of the victim that can be used to log in to their accounts — without requiring any passwords or an additional verification.

Kankrale also mentioned that the developer of the Mitron app isn't using the Secure Sockets Layer (SSL) protocol to secure the login. Although the app does allow users to login with their existing Google accounts, it processes the login through the unique user ID instead of using the provided Google account, he added.

Advertisement

He has also made a video showing the scope of the vulnerability that is yet to be fixed. He initially informed security-focussed site The Hacker News about the vulnerability.

Advertisement

Gadgets 360 didn't elicit a response from the email address provided on the Google Play listing of the Mitron app to get clarity on the flaw.

The Mitron app came into limelight as an India-made solution to counter TikTok. Some reports claimed that it was made by a student of IIT Roorkee. However, on Friday, it was reported that the app is not made in India and brought from a Pakistani software developer firm Qboxus.

Gadgets 360 doesn't recommend anyone to install and use the app that doesn't have any clarity about its makers and has at least one major vulnerability that is yet to be fixed.


Is Realme TV the best TV under Rs. 15,000 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Mitron app, TikTok, Mitron
Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. OnePlus Pad Go 2 First Impressions
  3. Jolla Phone Launched With 5,500mAh Replaceable Battery, Sailfish OS 5
  4. OnePlus Pad Go 2 Key Features Revealed: Here's When It Goes on Sale in India
  5. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  6. Xiaomi 17 Listed on Geekbench, Here's When It Might Launch in India
  7. Nicolas Cage Starrer Spider-Noir Set to Release on Prime Video in 2026
  8. Samsung's One UI 8.5 Beta Released: See Eligible Phones, Regions
  9. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  10. GTA 6 Roundup: Price in India, Launch Date, System Requirements and More
  1. Francis Lawrence’s The Long Walk (2025) Now Available for Rent on Prime Video and Apple TV
  2. Nicolas Cage Starrer Spider-Noir Set to Release on Prime Video in 2026
  3. Devi Chowdhurani OTT Release Date: When and Where to Watch Srabanti Chatterjee’s Period Drama Online?
  4. OnePlus Pad Go 2 Key Specifications and Sale Date Revealed; Will Feature Dimensity 7300-Ultra SoC
  5. OpenAI Claims Increased Enterprise Usage Amid CEO’s Code Red Declaration
  6. Samsung's One UI 8.5 Beta Update Rolls Out to Galaxy S25 Series in Multiple Regions
  7. Elon Musk Says Grok 4.20 AI Model Could Be Released in a Month
  8. Xiaomi 17 Global Variant Listed on Geekbench, Tipped to Launch in India by February 2026
  9. James Gunn's Superman to Release on JioHotstar on December 11: What You Need to Know
  10. The Boys Season 5 OTT Release Date: When and Where to Watch the Final Season Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.