Truecaller Fixes Flaw That Could Let Attackers Use Malicious Links to Harvest IP Addresses, Other User Data

The flaw was detected in one of Truecaller's APIs that could allow attackers to place malicious links as profile URL.

Advertisement
By Jagmeet Singh | Updated: 23 November 2019 13:23 IST
Highlights
  • Truecaller acknowledged the vulnerability and fixed the flaw
  • The flaw could let attackers fetch both IPv4 and IPv6 based IP addresses
  • Truecaller also revealed its plans to launch a bug bounty programme
Truecaller Fixes Flaw That Could Let Attackers Use Malicious Links to Harvest IP Addresses, Other User Data

Truecaller has over 150 million daily active users globally

Truecaller has fixed a flaw that could allow attackers to use the service's API to place a malicious link as the URL for their profile picture. The malicious link could be used to fetch IP addresses of other Truecaller users and perform attacks such as brute-force and distributed denial of service (DDoS), based on the obtained information. Further, the flaw could potentially enable the attackers to harvest IP addresses of users and scan for open ports. To exploit the flaw and attack a Truecaller user, a malicious party just had to lure a user to an infected profile.

The flaw existed in one of the APIs of Truecaller that allowed attackers to place their malicious links as the URL for a profile picture. Bengaluru-based security researcher Ehraz Ahmed discovered the Truecaller flaw and showed a proof-of-concept (PoC) to Gadgets 360.  Upon confirming the exploit was real, Gadgets 360 brought the flaw to Truecaller's attention and connected the company with the researcher. We then responsibly waited until the company had fixed the issue before publishing this article.

Attackers leveraging the flaw could fetch the IP addresses of users and silently obtain their location as well as device details. Because it was an API flaw, it could be accessed through all versions of Truecaller, including Android, iOS, and the Web.

Once IP address and other user data have been obtained through the flaw, an attacker could ascertain location details to track users viewing their profiles. The vulnerability could also be exploited to scan for open ports after accessing IP addresses to perform brute-force and DDoS attacks.

Advertisement

"Whenever a user views the attacker's profile on Truecaller -- either by doing a search or tapping the pop-up from a call, the custom script gets executed and user's IP address gets recorded," explains Ahmed, adding that the user wouldn't notice any difference as the profile URL is not displayed publicly.

To reproduce the flaw, Ahmed developed the PoC showing the process of recording IP addresses of users in a log file. The custom PHP script used by the security researcher worked with both IPv4 and IPv6 based IP addresses. Gadgets 360 was also able to verify the scope of the vulnerability by testing it through multiple Android and iPhone models. The custom script was able to obtain IP addresses of the devices alongside highlighting their model numbers and software versions.

Advertisement

In case if a user is searching for a Truecaller profile from a desktop, the flaw could let an attacker know about browser details. To showcase the extent of the flaw existing in Truecaller, Ahmed has created a video and published a case study.

 

"It was recently brought to our attention that there was a small bug in our app services which allowed the modification of one's own profile in an unintended way," Truecaller said in a statement to Gadgets 360. "We thank the security researcher for bringing this to our notice and collaborating with us. The bug was immediately fixed."

Advertisement

Truecaller also revealed that it is set to launch a bug bounty programme to reward security researchers reporting flaws in its system in the future.

"We, at Truecaller, are humbled to welcome all contributions from the security research community. We have partnered with a community of researchers and will shortly announce a bounty program where we, as a transparent and responsible organisation, will also reward researchers for their contributions," the company stated.

As of September this year, Truecaller has over 150 million daily active users globally. The Truecaller app also earlier this year crossed the mark of 500 million downloads and surpassed the milestone of one million Premium subscribers worldwide.

Truecaller is largely popular for its caller ID and call blocking features. Nevertheless, the app does offer Voice-over-Internet-Protocol (VoIP) based voice calling support and UPI-powered payments service to counter WhatsApp. Truecaller in April also tied up with Bengaluru-headquartered RedBus to start offering bus ticket booking service to its users in India.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Truecaller, Truecaller Flaw
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Ground Zero, Detective Sherdil, Found S2, and More
  2. Oppo Reno 14 5G Series Teased to Launch in India Soon
  3. 16 Billion Login Credentials Have Been Leaked in Massive Data Breach
  4. Vivo Y400 Pro 5G With 5,500mAh Battery Launched in India: Price, Features
  5. Vivo Y400 Pro 5G India Launch Today: All You Need to Know
  6. Nothing Phone 3 to Get New Glyph Matrix Interface on the Rear Panel
  7. Samsung Galaxy M36 5G India Launch Date and Key Features Revealed
  8. Samsung Galaxy S25 FE Leaked Render Suggests Improved Design
  9. Samsung Galaxy Z Flip 7 Leaked Renders Suggest Larger Cover Display
  10. Samsung Galaxy Z Fold 7 Leaked Renders Suggest Design Changes
  1. Adobe Launches Project Indigo, a Camera App for iPhone With Full Manual Controls
  2. Oppo Find X9 Pro Camera Details Leaked; Said to Feature Samsung ISOCELL HP5 Sensor
  3. Nintendo Switch 2 Third-Party Game Sales Reportedly 'Very Low' Despite Console's Record Launch
  4. 16 Billion Login Credentials Leaked in Massive Data Breach Impacting Apple, Google and More
  5. Vivo Y400 Pro 5G With 50-Megapixel Rear Camera, 5,500mAh Battery Launched in India: Price, Specifications
  6. Samsung Galaxy S25 FE Renders Leak Online, Suggesting Familiar Design With Thinner Bezels
  7. Samsung Galaxy Z Flip 7 Leaked Renders Suggest Edge-to-Edge Cover Display
  8. YouTube Shorts to Bring Google’s Veo 3 Video Generation Model With Audio Support 'This Summer'
  9. Samsung Galaxy Z Fold 7 Leaked Renders Hint at Design Changes; Storage Options Tipped
  10. Vivo Y400 Pro 5G Launching Today: Price in India, Expected Features and Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.