• Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Cyber Security

Analysis Reveals AirAsia App Being Exploited By Fraudsters, Riddled With Security Flaws

Along with potentially crippling security and privacy issues.

by John Law
December 12, 2024
AirAsia MOVE MOVETIX app
26
SHARES
Share on WhatsappShare on TelegramThreads

A static analysis conducted by Leakd is now suggesting that AirAsia’s official app is riddled with poor security and multiple privacy issues. Not only that, but threat actors have reportedly been able to fraudulently gain access to payment card details of several customers who used the app.

One AirAsia App user, who goes by the handle pastDepth9102 on Reddit, wrote in November that someone had tried to use their card for purchases in a Walmart outside of their home country. “This (credit card) has never been used anywhere else.”

Beware AirAsia Fraud
byu/PastDepth9102 inThailand

Another user, firealno9, said that they received a card authorisation request from Walmart as well, directly after they had booked a flight used the AirAsia app. Fortunately, knowing that their credit card details had been compromised, they promptly cancelled the card.

Leakd’s analysis revealed that the AirAsia app is putting out excessive requests for permissions such as READ_PHONE_STATE. It’s this request that supposedly allows threat actors to gather sensitive data from an individual’s device.

(Image source: PastDepth9102 via Reddit.)
AirAsia-App-compromised-2
(Image source: PastDepth9102 via Reddit.)

Leakd’s static analysis also revealed that the app had poor security practices and vulnerabilities which expose sensitive user data, weakening the app’s overall security structure. “Key issues include logging sensitive information, insecure WebView implementations, and the use of outdated or weak cryptographic algorithms such as MD5, SHA-1, and ECB mode encryption. Furthermore, the app demonstrates insecure handling of data storage, with world-readable and writable permissions on certain files, which could lead to unauthorized access or modification by malicious applications.”

At the time of writing, AirAsia has yet to officially comment on its app and its security flaws. In the mean time, you can do your part in staying financially safe by adopting the appropriate measures, including blocking your cards if they’ve been compromised, staying vigilant and monitoring your monetary transactions, and keeping your mobile devices up-to-date with the latest Android or iOS versions. Oh, and don’t click on any suspicious links, too.

RELATED:  AirAsia Offers Fixed-Fare Flights To Sabah, Sarawak For CNY, Hari Raya 2026

(Source: Leakd, Reddit)

Filed Under airasia
Updated 7:13 pm, Thu, 12 December 24
https://lowy.at/exsir
SendShareShareShare10Tweet7

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Fintech

    TNG Digital Retracts RON95 Subsidy Initiative, Issues Apology

  2. 2
    Fintech

    TNG eWallet Gets Physical Customer Service Hub At Kota Raya

  3. 3
    Telco

    China Mobile’s CMLink Now Offers Prepaid Plans In Malaysia; Priced From RM25/Month

  4. 4
    Hybrid Vehicles

    Honda Prelude Now Open For Booking In Malaysia

  5. 5
    Automotive

    Tesla Officially Launches Model Y L In Malaysia; Pricing To Start From RM260,000

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Editorial Policy
  • Terms of Use
  • Contact Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Banking
  • Fintech
  • Artificial Intelligence
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Banking
  • Fintech
  • Artificial Intelligence
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.