SonyLIV Fixes Flaw That Could Let Attackers Fetch Sensitive User Information

SonyLIV has over 100 million downloads on Google Play.

Advertisement
By Jagmeet Singh | Updated: 20 December 2019 17:14 IST
Highlights
  • SonyLIV had the flaw in one of its APIs used for login purposes
  • The flaw could be used to perform social engineering and other attacks
  • SonyLIV website and apps were affected by the vulnerability

SonyLIV has assured that the data of its subscribers remain safe and protected

SonyLIV has fixed a security flaw that could have allowed attackers to fetch sensitive user information such as profile picture, email address, date of birth, name, and phone number of its registered users. The flaw that existed in one of the APIs of the over-the-top (OTT) platform owned by Sony Pictures Networks could have been exploited simply using the email addresses of registered users. The platform uses the API to perform backend tasks such as providing the login option to existing users and fetching their account details. SonyLiv confirmed the fix to Gadgets 360 and assured that the data of its subscribers remain safe and protected.

“A bug that could have affected accounts using social media IDs for logging onto SonyLIV has been identified and removed. Data of all our subscribers remain safe and securely protected,” a SonyLIV spokesperson said in a prepared statement emailed to Gadgets 360.

The flaw was discovered by Bengaluru-based security researcher Ehraz Ahmed within the login process of SonyLIV. He showed a proof-of-concept (PoC) to Gadgets 360 last week. By passing a cURL request manually, Gadgets 360 was able to verify the vulnerability and notified SonyLiv of its its existence.

The IT team at SonyLIV started working on the fix soon after the issue was highlighted by Gadgets 360 and took a few days to make sure that it's been applied across all the apps and Web platforms. Since the flaw existed in the API designed for login functions, it had affected SonyLiv's mobile apps as well as its website.

Advertisement

Ahmed while speaking with Gadgets 360 underlined that finding the flaw was quite easy since SonyLIV didn't use any major security rules to protect backdoor access.

“The attackers could fetch sensitive user information in a few minutes using the vulnerability,” the researcher said.

Advertisement

After gaining access to the security loophole, a bad actor was required to just use the email addresses of one of the signed in SonyLIV users to gain their sensitive information. Additionally, the researcher explained that the vulnerability could be used to acquire the authentication token to gain full access to the user account. This means that the attackers would be able to log in to the user account using the authentication token by exploiting the reported flaw. The token could also be used to access other APIs of SonyLIV.

“It could cause a massive data breach, and the flaw was a risk to all the registered users as it could leak their sensitive information on the Web,” Ahmed told Gadgets 360. “The attackers could use the information fetched to even perform social engineering and other attacks.”

Advertisement

The researcher developed a script that was sending a request to the affected API and fetched user information along with the authentication token. He also created a video and published a case study detailing the flaw that both were unlisted and private until the fix was confirmed to Gadgets 360.

 

SonyLIV provides access to various TV shows that broadcast on channels owned by Sony Pictures Networks. Also, the platform, launched back in January 2013, provides access to live sports matches and live channels such as Animax HD, Sony BBC Earth, and Food Food among others. A paid subscription to SonyLIV is also available starting at Rs. 99 a month that brings access to live TV, premium shows, movies, and sports events.

The Android app of SonyLIV has over a 100 million downloads, as per the listing available on Google Play. However, the total number of registered users hasn't been disclosed.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. X Explores Stablecoin Payments for Influencers and Creators
  2. Here's When the Lava Bold N4 Lite Will Launch in India
  3. Infinix Hot 70 Pro India Launch Timeline Announced; Colourways Teased
  4. This Is When Apple Can Announce Its iPhone 18 Series Launch Event
  5. OnePlus Could Exclusively Launch Another 4G Phone in India Next Month
  6. iQOO Z11 Launched in India With These Features: See Price
  7. Qualcomm Teases Arrival of Two New Snapdragon 8 Elite Chips
  8. New GTA 6 Gameplay Leaks Emerge as Group Threatens to Release More Videos
  9. Huawei Pura X View Pre-Orders Start, Confirmed to Feature 7,000mAh Battery
  10. 7 ColorOS 16 Features You'll Wish Every Smartphone Had
  1. Vivo V2607 Geekbench Listing Reveals Key Details: What You Need to Know
  2. Elon Musk’s X Considers Stablecoin-Based Payments for Influencers and Content Providers
  3. Sony's Live Service Co-Op Game Horizon Hunters Gathering Reportedly Being Rebooted After Poor Player Feedback
  4. BitGo Becomes First Global Crypto Firm to Secure South Korea VASP Licence
  5. Huawei Pura X View Pre-Orders Begin; Confirmed to Feature Wide-Screen 16:9.5 Display, 7,000mAh Battery
  6. iQOO Gaming Tablet Tipped to Get Active Cooling, Snapdragon 8 Elite Gen 6 Pro SoC
  7. OnePlus Tipped to Launch a New 4G Phone Exclusively in India Next Month
  8. Qualcomm Teases Two New Snapdragon 8 Elite Chips Ahead of Snapdragon Summit
  9. Lava Bold N4 Lite India Launch Date Announced; Design and Durability Details Teased
  10. Coinbase Expands Tokenisation Push With Abu Dhabi Regulatory Approval
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.