Xbox Bug That Could Have Leaked Actual User Email IDs Through Gamer Tag Patched by Microsoft: Report

Microsoft patched a bug that was found on its enforcement.xbox.com portal where Xbox user can file complaints.

Advertisement
By Vineet Washington | Updated: 27 November 2020 14:18 IST
Highlights
  • Microsoft patched a bug that could leak user email IDs
  • The bug was found on enforcement.xbox.com
  • Hackers could potentially use Xbox gamer tags to find actual email IDs

Xbox user ID (XUID) field on the portal was unencrypted

Microsoft has reportedly patched a bug in an Xbox website that could have potentially exposed users' real email addresses associated to their Xbox gamer tags. This vulnerability was reported to the company through its bug bounty programme and has since been fixed. The findings for the bug that was reportedly found on enforcement.xbox.com were shared with an online publication earlier this week. The report explains that an Xbox user ID (XUID) field was unencrypted on enforcement.xbox.com.

According to a report by ZDNet, the bug in enforcement.xbox.com was spotted by Joseph "Doc" Harris and a team of security researchers. The website, enforcement.xbox.com, allows Xbox users to view strikes against their profile, as well as file appeals if in case they feel the strike is unfair. It was found that after a user logs in to the website, it creates a cookie file with details of the web session in their browser. This cookie file included an unencrypted Xbox user ID (XUID) field.

Harris was able to use standard browser tools to edit the XUID field and replace it with the XUID of a test account he had created for the Xbox bug bounty programme. Once he replaced the value and refreshed the page, emails of other users were visible. Check out the video by Harris detailing the same.

Advertisement

It was noted that other subdomains were not affected by this bug. The report states that Microsoft patched this bug last month and encrypted the XUID. It was a server-side fix and a Microsoft spokesperson told ZDNet that users do not need to do anything. Additionally, while the bug was not covered under the company's bug bounty programme, it featured Harris as a contributor in its Bug Bounty Hall of Fame. However, there was no monetary reward.

Advertisement

The bug had the potential to leak actual email IDs to hackers which could then be used for malicious purposes. What's alarming is that no special tool was required to get access to other user's email ID.


Which is the best TV under Rs. 25,000? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

 

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, Xbox, Xbox Gamer Tag
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  2. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  3. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  4. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  5. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  6. Realme Narzo 90, Realme Narzo 90x Launching Today: All You Need to Know
  7. Logitech MX Master 4 Launches in India With These Features
  8. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  9. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  10. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  1. Realme Narzo 90, Realme Narzo 90x 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Webb Telescope Discovers Hidden Atmosphere on Molten Super-Earth TOI-561 b Despite Extreme Heat
  3. Astronomers Watch a Dormant Neutron Star Reignite After a Decade of Silence
  4. Predictive Forecasting Tools Can Boost the Success of Clean Energy Investments Worldwide
  5. Chinese Spacecraft Nearly Slammed Into Starlink Satellite, SpaceX Reveals
  6. Clocks on Mars Run Faster Than on Earth, New Study Finds
  7. The Hunting Wives Out on OTT: Know Everything About This American Thriller Mystery Series
  8. All Her Fault Now Streaming on JioHotstar: Know Everything About This Thriller Series
  9. Wednesday Season 3 Set for July 2027 on Netflix: Jenna Ortega Returns as the Iconic Addams Heir
  10. Lakshmi Manchu’s Daksha: The Deadly Conspiracy Available for Streaming on Amazon Prime Video
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.