Skip to main content

Marriott’s Android app left customers’ credit card information wide open for years

Marriottheadquarters
Image used with permission by copyright holder
Marriott’s already been in hot water as of late, thanks to its decision to block personal Wi-Fi hotspots, a decision that led to an FCC fine of $600,000. Now, Marriott finds itself in even deeper hot water as a software developer discovered a vulnerability in its Android app, which reportedly left credit card information open for hackers to nab for years.

According to Randy Westergren, who is the software developer in question, he discovered the vulnerability after he logged into the app using only his Membership ID number. After doing so, he realized the app made a request to fetch reservations, even though he had none. He discovered that the app was fetching reservations through unauthenticated requests, which means he could type in a different Membership ID and send it to the server. By doing so, Westergren could find out a customer’s reservation, the hotel where they will be staying at, and the check-in time.

Recommended Videos

Once he had this information, Westergren could easily log into Marriott’s website with it, since the site only requires a last name and reservation number to log in. Doing so granted Westergren the ability to cancel planned trips and obtain addresses, credit card numbers, and customer information. Granted, only the last four digits of their credit cards would be revealed, but that would be more than plenty for hackers to work with.

Thankfully, according to Westergren, Marriott fixed the issue a day after his report saw the light of day. We’ve yet to read or receive any reports of compromised accounts, so if you frequently use the Marriott app, your information should be safe. Even so, thinking about how the app first launched back in 2011 with this vulnerability doesn’t exactly make anyone very happy, to say the least.

Williams Pelegrin
Former Digital Trends Contributor
Williams is an avid New York Yankees fan, speaks Spanish, resides in Colorado, and has an affinity for Frosted Flakes. Send…
The Spotify Android app just got an odd design change
A close-up of the Spotify app icon.

There's a good chance you use Spotify for your music streaming and podcast listening. There's also a good chance you use the Spotify app on your Android phone. If so, you'll soon notice that the app looks a bit different than usual.

How so? The app icon no longer has its distinctive black background. Gasp.

Read more
The Google app on your Android phone is getting a helpful new feature
Google app on Android beta showing Notifications.

The Google app for Android phones is getting a helpful new feature to make search even better. The latest beta has a dedicated "Notifications" feed in its bottom bar. The feature was first introduced on the mobile version of Google for Android earlier this year. The app feature was first noticed by 9to5Google.

The app now includes a Notifications option at the bottom, next to Discover, Search, and Saved items. The Notifications section displays a continuous list of alerts from Google Search, weather conditions, flight information, sports scores, movies and TV shows, and more. The notifications are grouped under “Today” and “Earlier." This feature should prove handy if you miss a notification from the Google app, as it provides a more focused view than Android's system-level history.

Read more
How to get Android apps on a Chromebook
Dell Chromebook 3189 2-in-1 on a classroom desk floating in the air.

Over the last few years, Android apps have been added to more and more Chromebook models. A brilliant expansion of the overall user experience, Google went ahead and integrated the Play Store into most Chromebooks made after 2019. This is the most convenient way to download an Android app or two, but if you own an older Chromebook, the machine may not have native support for downloading and installing applets.

To confirm this, we recommend referencing this extensive Android app support list from The Chromium Projects.

Read more