Uber Account Takeover Bug Found by Indian Researcher, Now Fixed

Uber paid Anand Prakash $6,500 i.e. about Rs 4.6 lakh as a reward for giving information about this bug.

Advertisement
By Gadgets 360 Staff With Inputs From IANS | Updated: 16 September 2019 17:50 IST

Global ride-hailing giant Uber has recently fixed a hacking bug found by Indian cyber-security researcher Anand Prakash which allowed hackers to log into anyone's Uber account.

Uber has paid Prakash $6,500, i.e. about Rs 4.6 lakh as a reward for giving information about this bug.

Advertisement

Prakash explained that the bug was an account-takeover-vulnerability on Uber that allowed attackers to take over any other user's Uber account, including those of partners and Uber Eats users, Inc42 reported.

As per Prakash's blog, the bug was present in the API request function of the Uber app. Prakash describes "an account takeover vulnerability on Uber which allowed attackers to take over any other user's Uber account (including riders, partners, eats) account by supplying user UUID in the API request and using the leaked token in the API response to hijack accounts. We were able to enumerate any other Uber's user UUID by supplying their phone number or email address in another API request."

Advertisement

He added that the bug "allowed an attacker to track the victim's location, take rides from their account, etc. by compromising the account using the leaked access token of Uber mobile application. This also permitted takeover of Uber driver, Eats accounts."

According to a statement provided by an Uber spokesperson to Inc42, "The bug was quickly fixed through Uber's bug bounty program, which has paid over $2M USD to more than 600 researchers around the world, including top researchers in India. We are grateful for their contributions to help protect the Uber platform.”

Advertisement

Earlier Prakash had removed a bug in Uber, by taking advantage of which anyone could travel for free for a lifetime in an Uber cab.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Uber, Anand Prakash
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  3. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets
  4. Vivo X300 FE Roundup: Expected Price in India, Specifications
  5. Xiaomi TV S Mini LED 75 (2026) Review
  6. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  7. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC
  1. Spotify Ads Manager Platform Launched in India, Brings Self-Serve Advertising to Businesses
  2. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets; Ends Day-One Call of Duty Access
  3. Incoming Apple CEO John Ternus Already Driving AI Overhaul Ahead of Leadership Transition: Report
  4. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  5. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  6. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  7. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  8. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  9. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  10. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.