Skip to main content

TrueCaller patches exploit that left millions of Android users vulnerable

truecaller exploit patched
Image used with permission by copyright holder
It seems as though every other day, there’s some kind of potential threat to an Android user’s security. Another security exploit was recently uncovered, but this time it’s related to a dialer app called TrueCaller.

While it’s not malware-related, installing TrueCaller could have left you susceptible to malicious hackers. Cheetah Mobile’s Security Research Lab found a loophole in the app that would have allowed anyone to gain access to TrueCaller user’s private information. TrueCaller used a smartphone’s IMEI number as the identity label of its users.

TrueCaller tells you who’s calling. It does so by identifying numbers, and matching them with ones marked by users. You can mark numbers as spam to make the service better and more reliable. As it crowd-sources its data, TrueCaller users have accounts with their name, phone number, home address, gender, and more — it’s this data that was available to malicious hackers through the app’s loophole.

If someone managed to get hold of your IMEI number, they could go to TrueCaller’s website and access all of that information in your account, and even modify it — potentially lifting spam blocks so those calls can make it through again.

Thankfully, TrueCaller has patched the issue, and you should download the latest update through the Google Play store to make sure you’re safe. The company says no user information was compromised.

“We recently found an issue where some user defined information can be retrieved or changed without the original user’s consent, if a third person knows the IMEI number of the original person’s device,” according to the blog post. “We’ve quickly taken steps to fix this issue and have released an update which we strongly suggest all users upgrade to.”

What makes it scary is that more than 100 million Android users who have downloaded the app were vulnerable, and likely more as TrueCaller has been making its way to Cyanogen OS, in phones like Wileyfox, and Blu devices. TrueCaller is also available for Windows, and iOS, but it looks like the app on those operating systems were not affected.

Editors' Recommendations

Julian Chokkattu
Former Digital Trends Contributor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
Forget the Galaxy Z Flip 5: The Motorola Razr is only $500 today
Split screen apps on the Motorola Razr 40.

Looking for great phone deals on stylish phones? Check out the Motorola Razr which is currently down to $500 when you buy direct from Motorola. Normally priced at $700, you’re saving $200 off the regular price which is a pretty sweet deal indeed. If you’re keen to learn more about the stylish phone, here’s what you need to know.

Why you should buy the Motorola Razr
Considered to be one of the best Android phones for anyone considering a cheap foldable Android phone, the Motorola Razr looks great. It’s lightweight and compact being a folding Android phone that isn’t incredibly expensive.

Read more
This 5G phone just had its price slashed to $150 for a limited time
Moto G 5G (2024) in Sage Green showing notifications.

For super cheap phone deals, go straight to the source and head to Motorola. Right now, you can buy the Moto G 5G phone for just $150, saving you $100 off the regular price of $250. For a budget phone, it’s ideal to keep you happy with necessities like web browsing, social media, text and calls. Here’s everything else you need to know about it.

Why you should buy the Moto G 5G
You won’t see the Moto G 5G on our look at the best Android phones as it’s pretty basic. At this price though, that’s hardly surprising. It has the essentials covered well. There’s a 6.4-inch HD+ screen which looks pretty good for the price. That’s helped by its 120Hz refresh rate which means you get smooth scrolling and no motion blur when watching videos or playing games. Alongside that are two large stereo speakers so you can be suitably entertained here. There’s also Dolby Atmos support to provide more immersive sound.

Read more
Apple’s new iPad Air isn’t even out yet and it’s already discounted
An official photo of the 2024 iPad Air.

We love iPad deals at any time, but how about an iPad deal on a recently announced model? That’s what’s going on right now at Amazon with the Apple iPad Air 11-inch M2 -- reduced by $29 when it hasn’t even been launched yet. Normally priced at $599, you can buy it -- or should we say, pre-order it -- for $570 today. That’s how new it is. If you’re keen to buy a new iPad for less, read on while we take you through what to expect.

Why you should buy the Apple iPad Air 11-inch M2
Only recently announced, the Apple iPad Air 11-inch M2 is sure to be something special. We’ve compared the iPad Air (2024) with the iPad Air (2022) to see why it’s so great. Effectively, the killer feature here is that it has the Apple M2 chip we’ve seen in more recent MacBooks compared to the older M1 chipset. That makes it a great option for power users who want all the power possible from one of the best tablets.

Read more