Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Fake WhatsApp API package on npm steals messages, contacts, and login tokens

TikTok Shop launches digital gift cards to compete with Amazon and eBay

Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Security flaw in Freedom Chat app exposes users’ phone numbers and PINs
Startups

Security flaw in Freedom Chat app exposes users’ phone numbers and PINs

userBy userDecember 11, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Messaging app Freedom Chat has fixed two security flaws. One allowed security researchers to guess registered users’ phone numbers, and the other allowed users to set a PIN and make it available to other users on the app.

Released in June, Freedom Chat advertises itself as a secure messaging app, and its website claims that users’ phone numbers are kept private.

However, security researcher Eric Daigle told TechCrunch that the user’s phone number and PIN code used to lock the app could be easily obtained by exploiting the vulnerability.

Daigle discovered the vulnerability last week and shared its details with TechCrunch, as Freedom Chat does not offer a public means to report security flaws like a vulnerability disclosure program. TechCrunch later alerted Freedom Chat founder Tanner Haas about the security flaw in an email.

Haas confirmed to TechCrunch that the app reset user PINs and released a new version. Haas added that the company is removing instances where a user’s phone number is occasionally displayed and is gradually tightening rate limits on its servers to prevent mass guessing attempts.

Daigle, who published his findings in a blog post, told TechCrunch that he was able to list the phone numbers of nearly 2,000 users who have signed up to use Freedom Chat since its launch. Daigle said Freedom Chat’s servers allowed anyone to submit millions of phone number guesses in order to determine if a user’s phone number was stored on the server.

Daigle said the technique is identical to one published in a study last month by the University of Vienna, in which academics collected data on the roughly 3.5 billion user accounts who signed up for WhatsApp by matching billions of phone numbers with WhatsApp’s servers.

Daigle also discovered that Freedom Chat was leaking users’ PIN codes. Using open-source network traffic inspection tools to analyze data flowing into and out of the app, Daigle found that the app responded with the PIN code of every other user in the same public channel, even if the PIN was not visible to the user within the app itself.

According to Daigle, anyone who joined the default Freedom Chat channel, which users are automatically subscribed to when they first sign up, had their PIN broadcast to everyone else in the channel. Daigle told TechCrunch that knowing a person’s PIN could allow them to open apps from the user’s stolen device.

In an app store update published on Sunday, Freedom Chat said, “Critical reset: A recent backend update inadvertently exposed a user’s PIN in a system response. At no time were their messages ever compromised. And because Freedom Chat does not support linked devices, they were unable to access their conversations. However, we have reset the PIN for all users to ensure the safety of their accounts. Your privacy remains our top priority.”

Freedom Chat is Haas’ second messaging app, following Converso, which was removed from the app store following the disclosure of security flaws that exposed users’ private messages and content.


Source link

#Aceleradoras #CapitalRiesgo #EcosistemaStartup #Emprendimiento #InnovaciónEmpresarial #Startups
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleNANOREMOTE malware uses Google Drive API for hidden controls on Windows systems
Next Article Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More Stories
user
  • Website

Related Posts

TikTok Shop launches digital gift cards to compete with Amazon and eBay

December 22, 2025

A tough week for hardware companies

December 21, 2025

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

December 21, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Fake WhatsApp API package on npm steals messages, contacts, and login tokens

TikTok Shop launches digital gift cards to compete with Amazon and eBay

Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More

How to browse the web more sustainably with a green browser

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.