+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Those new Kardashian and Jenner websites just exposed the personal data from nearly 900,000 subscribers

Sep 17, 2015, 19:11 IST

E!/YouTube

The new Kardashian and Jenner apps have been taking over the App Store like a rampaging army, with Kylie Jenner's app rocketing up to the number one spot.

Advertisement

Both the Kardashians and Jenners also released their own personal websites to go along with their new apps, but a security flaw has reportedly exposed the personal information of all the first 891,240 users, according to TechCrunch. The information includes first and last names, as well as email addresses.

A developer named Alaxic Smith discovered the security bug by poking around on the Kardashian and Jenner websites (associated with the apps), according to Fortune. He found an unsecure part of the site which contained partial login information for all app users.

"Initially, I thought that this was some page filled with dummy data, but as I started to look closer, I realized it wasn't," he wrote on Medium (the post has since been taken down). "I now had access to the first names, last names, and email addresses of the 663,270 people who signed up for Kylie Jenner's website." He also found he could create or destroy users' photos and videos, he wrote.

Smith then confirmed that all the sisters' sites, which were made by Whalerock Industries, had the same flaw. The company has since addressed the issue, and issued this statement to TechCrunch:

Advertisement

Shortly after launch we were alerted that there was an open Api. It was promptly closed. Our logs indicate that the author of the blog post was able to access only a limited set of names and email addresses. Our logs further indicate no one else had access and that no passwords nor payment data of any kind was exposed. Our highest priority is the security of our customers' data.

NOW WATCH: People were baffled by 50 sharks circling in shallow waters off the English coast

Please enable Javascript to watch this video
You are subscribed to notifications!
Looks like you've blocked notifications!
Next Article