Flawed Credential Storage In Top Android Apps Puts Users At Risk Comparitech
1,057 out of 2,500 top and trending apps on Google Play leak at least one secret credential, such as an access token or password, according to Comparitech researchers. These secrets could be used by malicious hackers to attack apps, APIs, and end users. We often think of “credentials” as the information we need to log into an app or website, such as your email address and password. But credentials also include passwords and tokens used by apps themselves to authenticate various connections to first- and third-party servers, APIs, and other endpoints....