Uber Account Takeover Bug Found by Indian Researcher, Now Fixed

Uber paid Anand Prakash $6,500 i.e. about Rs 4.6 lakh as a reward for giving information about this bug.

Advertisement
By Gadgets 360 Staff With Inputs From IANS | Updated: 16 September 2019 17:50 IST

Global ride-hailing giant Uber has recently fixed a hacking bug found by Indian cyber-security researcher Anand Prakash which allowed hackers to log into anyone's Uber account.

Uber has paid Prakash $6,500, i.e. about Rs 4.6 lakh as a reward for giving information about this bug.

Prakash explained that the bug was an account-takeover-vulnerability on Uber that allowed attackers to take over any other user's Uber account, including those of partners and Uber Eats users, Inc42 reported.

Advertisement

As per Prakash's blog, the bug was present in the API request function of the Uber app. Prakash describes "an account takeover vulnerability on Uber which allowed attackers to take over any other user's Uber account (including riders, partners, eats) account by supplying user UUID in the API request and using the leaked token in the API response to hijack accounts. We were able to enumerate any other Uber's user UUID by supplying their phone number or email address in another API request."

Advertisement

He added that the bug "allowed an attacker to track the victim's location, take rides from their account, etc. by compromising the account using the leaked access token of Uber mobile application. This also permitted takeover of Uber driver, Eats accounts."

According to a statement provided by an Uber spokesperson to Inc42, "The bug was quickly fixed through Uber's bug bounty program, which has paid over $2M USD to more than 600 researchers around the world, including top researchers in India. We are grateful for their contributions to help protect the Uber platform.”

Advertisement

Earlier Prakash had removed a bug in Uber, by taking advantage of which anyone could travel for free for a lifetime in an Uber cab.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Further reading: Uber, Anand Prakash
Advertisement

Related Stories

Popular Mobile Brands
  1. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  2. Samsung Galaxy A37, Galaxy A57 Get Better Geekbench Scores Ahead of Debut
  3. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  4. Vivo X300 FE Launched as Global Version of This Chinese Smartphone
  5. MacBook Pro (2026) With M5 Pro, M5 Max Chips Launched in India: See Price
  1. Hubble Constant Puzzle Deepens as Supernova and CMB Measurements Clash
  2. MacBook Neo Launched in India With 13-Inch Liquid Retina Display, Apple's A18 Pro Chip: Price, Specifications
  3. Samsung Galaxy A37, Galaxy A57 Spotted on Geekbench With Better Results Ahead of Anticipated Launch
  4. Vivo X300 FE Launched With Snapdragon 8 Gen 5, 50-Megapixel Telephoto Camera: Price, Features
  5. Vivo V70 FE Colour Options, Key Specifications Revealed Ahead of March 9 Launch
  6. Apple MacBook Neo Reportedly Listed on Regulatory Site Hours Before Anticipated Launch
  7. Tecno Pop X Launched in India With 5,000mAh Battery, IP64 Rating: Price, Specifications
  8. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Unveiled at MWC 2026: Availability, Features
  9. Mike & Nick & Nick & Alice OTT Release Date: Know When and Where to Watch it Online
  10. MediaTek Showcases AI Glasses at MWC 2026; Demonstrates Emergency Satellite Alerts With Starlink
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.