Tuesday, July 22, 2025
  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Cyber Security

Analysis Reveals AirAsia App Being Exploited By Fraudsters, Riddled With Security Flaws

Along with potentially crippling security and privacy issues.

by John Law
December 12, 2024
AirAsia MOVE MOVETIX app
353
SHARES
Share on FacebookShare on Twitter

A static analysis conducted by Leakd is now suggesting that AirAsia’s official app is riddled with poor security and multiple privacy issues. Not only that, but threat actors have reportedly been able to fraudulently gain access to payment card details of several customers who used the app.

One AirAsia App user, who goes by the handle pastDepth9102 on Reddit, wrote in November that someone had tried to use their card for purchases in a Walmart outside of their home country. “This (credit card) has never been used anywhere else.”

Beware AirAsia Fraud
byu/PastDepth9102 inThailand

Another user, firealno9, said that they received a card authorisation request from Walmart as well, directly after they had booked a flight used the AirAsia app. Fortunately, knowing that their credit card details had been compromised, they promptly cancelled the card.

Leakd’s analysis revealed that the AirAsia app is putting out excessive requests for permissions such as READ_PHONE_STATE. It’s this request that supposedly allows threat actors to gather sensitive data from an individual’s device.

(Image source: PastDepth9102 via Reddit.)
AirAsia-App-compromised-2
(Image source: PastDepth9102 via Reddit.)

Leakd’s static analysis also revealed that the app had poor security practices and vulnerabilities which expose sensitive user data, weakening the app’s overall security structure. “Key issues include logging sensitive information, insecure WebView implementations, and the use of outdated or weak cryptographic algorithms such as MD5, SHA-1, and ECB mode encryption. Furthermore, the app demonstrates insecure handling of data storage, with world-readable and writable permissions on certain files, which could lead to unauthorized access or modification by malicious applications.”

At the time of writing, AirAsia has yet to officially comment on its app and its security flaws. In the mean time, you can do your part in staying financially safe by adopting the appropriate measures, including blocking your cards if they’ve been compromised, staying vigilant and monitoring your monetary transactions, and keeping your mobile devices up-to-date with the latest Android or iOS versions. Oh, and don’t click on any suspicious links, too.

ALSO READ:  AirAsia MOVE Sales Halted In Philippines Over “Criminal” Fares

(Source: Leakd, Reddit)

Filed Under airasia
Updated 7:13 pm, Thu, 12 December 24
https://lowy.at/exsir
Share141Tweet88SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    Fintech

    TNG Digital, Kakitangan.com Introduce Salary Payouts Via TNG eWallet

  2. 2
    Automotive

    Honda HR-V Facelift Debuts In Malaysia; Starts From RM115,900

  3. 3
    Hybrid Vehicles

    Lamborghini Temerario Debuts In Malaysia; Priced At RM1.35 Million

  4. 4
    News

    Four Remanded In RM180 Million Data Centre Bribery Probe

  5. 5
    Transportation

    MRT3 Circle Line Gets Final Approval From The Ministry Of Transport

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.