Top mobile finance app Money Lover has some worrying security flaws

dollar
Image Credit: Akspic (Image credit: Future)

A popular finance and budgeting mobile app was leaking email addresses and other sensitive data to anyone who was logged in to the platform, researchers discovered earlier this week.

As reported on BleepingComputer, cybersecurity researchers from Trustwave were looking into the traffic of an Android, iOS, and Windows app called Money Lover using a proxy and the Web Sockets view in the browser's Developer Tools, when they stumbled upon a quickly populating list of email addresses and other data. Further investigation uncovered that the emails belonged to users of the so-called “shared wallet” feature.

Shared wallets leaking

As a finance and budgeting app, Money Lover allows multiple users to collaborate on a single, shared wallet. Think of it as a wallet for the home budget, where multiple household members can log their expenses and track overall spending. As expected, users sharing the same wallet can see each other’s emails. However, so can anyone else who’s logged in to the platform, and that’s the problem. What’s more, researchers have found that live transaction metadata was also being broadcast.

"The shared wallet transactions disclose user information, such as the user's email address and shared wallet name," Trustwave reported. "The email address and shared wallet name can be viewed via the Web Sockets tab of the browser's "Developer Tools." All Money Lover users who make use of the Shared Wallet feature are affected by this issue."

The researchers did not say when they discovered the vulnerability, or how many users were affected. What we do know is that Money Lover was downloaded more than five million times on the Google Play Store, alone. 

To keep their emails safe, users are advised to update the app to the latest version as soon as possible, otherwise their email addresses might get bombarded with phishing emails and malware infection attempts.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
mobile phone
Popular Android financial help app is actually dangerous malware
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection