Money Lover for Android & iOS leaked email addresses, transactions

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,617
A flaw in the Money Lover financial app for Android, iOS, and Windows allowed any logged-in member to see the email addresses and live transaction metadata for other users' shared wallets.

Money Lover is a finance app allowing users to manage their expenses and budgets that has been downloaded five million times on the Play Store, with the app also available for iOS and Windows.

Money Lover allows users to create "shared wallets" with specific users, like family members or coworkers, to log transactions to collaborate in expense logging and monitoring.

Users invited to a shared wallet typically know each other, so sharing data and email addresses are expected.

However, Trustwave's analyst and Money Lover user, Troy Driver, found that transaction data and email addresses associated with shared wallets are exposed to any authenticated users of the app.
Trustwave reported the issue to the publisher of Money Lover, Finsify, who released a fixing update on January 27, 2023.

The report did not clarify when the flaw was discovered or how long Money Lover users remained exposed.

It is essential to clarify that the information disclosure bug only impacted users who used the shared wallet feature.

The main repercussion of this flaw is that an attacker accessing email addresses and transaction metadata could perform targeted phishing attacks against the exposed users to gain access to further sensitive information.

Money Lover users are recommended to update their app to the latest available version using their operating system's app store.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top