logo

Mobile security vulnerabilities threaten millions in Latin America: ICFP and Citizen Lab fellow Beau Kujath finds security vulnerabilities in mobile applications in Latin America region.

ID: a09879e0-9514-5db9-bb42-0f1b0ddae42d

STIX ID: report--a09879e0-9514-5db9-bb42-0f1b0ddae42d

Feed Name: The Citizen Lab

Threat Score
70/100

Date Published: 2024-01-12

Date Updated: 2026-04-19

Author: Snigdha Basu

...
...

Citizen Lab and an Open Technology Fund fellow analyzed popular Latin American mobile applications and found systemic security and privacy issues: several telecom apps use cleartext HTTP (allowing eavesdropping and injection), apps transmit personal data to third-party servers contrary to stated privacy claims, a Salvadoran crypto wallet uses Microsoft CodePush enabling remote updates outside app-store controls, and SMS-delivered links in multiple apps are vulnerable to SSL-strip attacks — collectively exposing millions of users to data leakage, manipulation, and potential supply-chain style compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.