HomeLatest NewsCyber SecuritySecurity flaw in mAadhaar app can allow hackers to steal your Aadhaar data: Security researcher

Security flaw in mAadhaar app can allow hackers to steal your Aadhaar data: Security researcher

A Security researcher alias Elliot Alderson has tweeted a serious security vulnerability in UIDAI’s mAadhaar app for Android devices.

Preferred Source of Google

A Security researcher alias Elliot Alderson has tweeted a serious security vulnerability in UIDAI‘s mAadhaar for Android devices. According to the researcher, the Aadhaar mobile app is saving user sensitive data including the biometric data in a password protected local database. The password for the database is generated using a random number “123456789 as seed” and a hardcoded string db_password_123 which remains same for every phone.

Besides this, Elliot has also uploaded a proof-of-concept on Github to demonstrate the flaw. He made an application with the exact same code as was written in the to prove that even if you run it multiple times, it will give you the same password over and over again instead of the randomised password the app is supposed to generate.

The researcher has stated that if a person is able to crack the password, they can access the entire Aadhaar account details of the user. He further said that as per the documentation for the mAadhaar app, the app will store personal details and the user’s photo in their local database.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

UIDAI has however confirmed that the app creates a local database with innocuous data like user preferences. Further, they said that since the app doesn’t ask for any biometric data, such data can’t be compromised.

According to Ankush Johar, Director at Infosec Ventures, although the exploitability of this issue is pretty low, nonetheless, information as critical as Biometrics along with other PII is something that should not be exposed to even the slightest risk.

Advertisement

“Recently, with alleged leakage of Aadhaar details of over a billion citizens, hackers might already have access to every information printed on our Aadhaar cards and can easily replicate it. Even though a person has replicated your , he/she will still need your Biometric info for authentication. If by any chance the hackers are able to gain the biometric data as well, then it will catastrophic,” said Johar.

He further said, “As the UP cloning fraud showed us that making a physical clone of the fingerprints is not too difficult, such leakage could do irreversible damage as you can change your passwords but you cannot change your fingerprints.”

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Sanjay Singh
Sanjay Singh
Sanjay Singh covers startups, consumer electronics and telecom for TechObserver.in
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

Meta Launches AI Glasses at $299 with EssilorLuxottica Partnership

Meta has launched AI-powered smart glasses starting at $299 in partnership with EssilorLuxottica, featuring three frame styles and a collaboration with Kylie Jenner. The glasses run on Meta AI powered by the company's new Muse Spark model.

RELATED ARTICLES