Wednesday, August 13, 2025
  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Cyber Security

Analysis Reveals AirAsia App Being Exploited By Fraudsters, Riddled With Security Flaws

Along with potentially crippling security and privacy issues.

by John Law
December 12, 2024
AirAsia MOVE MOVETIX app
356
SHARES
Share on FacebookShare on Twitter

A static analysis conducted by Leakd is now suggesting that AirAsia’s official app is riddled with poor security and multiple privacy issues. Not only that, but threat actors have reportedly been able to fraudulently gain access to payment card details of several customers who used the app.

One AirAsia App user, who goes by the handle pastDepth9102 on Reddit, wrote in November that someone had tried to use their card for purchases in a Walmart outside of their home country. “This (credit card) has never been used anywhere else.”

Beware AirAsia Fraud
byu/PastDepth9102 inThailand

Another user, firealno9, said that they received a card authorisation request from Walmart as well, directly after they had booked a flight used the AirAsia app. Fortunately, knowing that their credit card details had been compromised, they promptly cancelled the card.

Leakd’s analysis revealed that the AirAsia app is putting out excessive requests for permissions such as READ_PHONE_STATE. It’s this request that supposedly allows threat actors to gather sensitive data from an individual’s device.

(Image source: PastDepth9102 via Reddit.)
AirAsia-App-compromised-2
(Image source: PastDepth9102 via Reddit.)

Leakd’s static analysis also revealed that the app had poor security practices and vulnerabilities which expose sensitive user data, weakening the app’s overall security structure. “Key issues include logging sensitive information, insecure WebView implementations, and the use of outdated or weak cryptographic algorithms such as MD5, SHA-1, and ECB mode encryption. Furthermore, the app demonstrates insecure handling of data storage, with world-readable and writable permissions on certain files, which could lead to unauthorized access or modification by malicious applications.”

At the time of writing, AirAsia has yet to officially comment on its app and its security flaws. In the mean time, you can do your part in staying financially safe by adopting the appropriate measures, including blocking your cards if they’ve been compromised, staying vigilant and monitoring your monetary transactions, and keeping your mobile devices up-to-date with the latest Android or iOS versions. Oh, and don’t click on any suspicious links, too.

ALSO READ:  AirAsia MOVE Refutes Fare Manipulation Claims

(Source: Leakd, Reddit)

Filed Under airasia
Updated 7:13 pm, Thu, 12 December 24
https://lowy.at/exsir
Share142Tweet89SendShare

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    News

    You Can Now Apply To Switch To TNB ToU Billing Via myTNB Portal

  2. 2
    Mobile Phones

    Redmi 15 5G Now Official And Available For RM729 In Malaysia

  3. 3
    Audio

    Sony Launches Limited Hatsune Miku Digital Models With LinkBuds Fit; Priced At RM999

  4. 4
    Automotive

    GAC Malaysia Showcases Emkoo And M8 PHEV At One Utama Roadshow

  5. 5
    Rumours & Leaks

    NVIDIA Reportedly Planning “Aggressive” Price Cuts For RTX 50 Series GPUs

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Miss Murai
  • Varnam
  • Moviedash
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Contact Us
  • Editorial Policy
  • Terms & Conditions

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zone
    • Viewnet
    • Sri Computers
    • Startec
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables

©2025 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.