SonyLIV Fixes Flaw That Could Let Attackers Fetch Sensitive User Information

SonyLIV has over 100 million downloads on Google Play.

Advertisement
By Jagmeet Singh | Updated: 20 December 2019 17:14 IST
Highlights
  • SonyLIV had the flaw in one of its APIs used for login purposes
  • The flaw could be used to perform social engineering and other attacks
  • SonyLIV website and apps were affected by the vulnerability

SonyLIV has assured that the data of its subscribers remain safe and protected

SonyLIV has fixed a security flaw that could have allowed attackers to fetch sensitive user information such as profile picture, email address, date of birth, name, and phone number of its registered users. The flaw that existed in one of the APIs of the over-the-top (OTT) platform owned by Sony Pictures Networks could have been exploited simply using the email addresses of registered users. The platform uses the API to perform backend tasks such as providing the login option to existing users and fetching their account details. SonyLiv confirmed the fix to Gadgets 360 and assured that the data of its subscribers remain safe and protected.

“A bug that could have affected accounts using social media IDs for logging onto SonyLIV has been identified and removed. Data of all our subscribers remain safe and securely protected,” a SonyLIV spokesperson said in a prepared statement emailed to Gadgets 360.

The flaw was discovered by Bengaluru-based security researcher Ehraz Ahmed within the login process of SonyLIV. He showed a proof-of-concept (PoC) to Gadgets 360 last week. By passing a cURL request manually, Gadgets 360 was able to verify the vulnerability and notified SonyLiv of its its existence.

Advertisement

The IT team at SonyLIV started working on the fix soon after the issue was highlighted by Gadgets 360 and took a few days to make sure that it's been applied across all the apps and Web platforms. Since the flaw existed in the API designed for login functions, it had affected SonyLiv's mobile apps as well as its website.

Advertisement

Ahmed while speaking with Gadgets 360 underlined that finding the flaw was quite easy since SonyLIV didn't use any major security rules to protect backdoor access.

“The attackers could fetch sensitive user information in a few minutes using the vulnerability,” the researcher said.

Advertisement

After gaining access to the security loophole, a bad actor was required to just use the email addresses of one of the signed in SonyLIV users to gain their sensitive information. Additionally, the researcher explained that the vulnerability could be used to acquire the authentication token to gain full access to the user account. This means that the attackers would be able to log in to the user account using the authentication token by exploiting the reported flaw. The token could also be used to access other APIs of SonyLIV.

“It could cause a massive data breach, and the flaw was a risk to all the registered users as it could leak their sensitive information on the Web,” Ahmed told Gadgets 360. “The attackers could use the information fetched to even perform social engineering and other attacks.”

Advertisement

The researcher developed a script that was sending a request to the affected API and fetched user information along with the authentication token. He also created a video and published a case study detailing the flaw that both were unlisted and private until the fix was confirmed to Gadgets 360.

 

SonyLIV provides access to various TV shows that broadcast on channels owned by Sony Pictures Networks. Also, the platform, launched back in January 2013, provides access to live sports matches and live channels such as Animax HD, Sony BBC Earth, and Food Food among others. A paid subscription to SonyLIV is also available starting at Rs. 99 a month that brings access to live TV, premium shows, movies, and sports events.

The Android app of SonyLIV has over a 100 million downloads, as per the listing available on Google Play. However, the total number of registered users hasn't been disclosed.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.