logo

Mobile App Wall Of Shame: Quikr

ID: aa710d99-3533-5a72-97a9-e91d849b852c

STIX ID: report--aa710d99-3533-5a72-97a9-e91d849b852c

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Quikr's Android (consumer version ~7.42) and iOS (version 2.8) mobile apps were found to send sensitive user data — including user IDs, passwords and mobile numbers — in cleartext over HTTP during registration and login. Traffic captures and Zscaler Application Profiler (ZAP) screenshots confirm the exposure; the issue affects millions of Android users and risks credential interception. The report recommends mitigation measures such as using one-time passwords and unique credentials to reduce impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.