10th Indian Delegation to Dubai, Gitex & Expand North Star – World’s Largest Startup Investor Connect
Gadgets

Cert-In warns of critical security flaw in these two government apps



India Computer Emergency Response Team (CERT-In) has reported ‘high’ severity security flaws within two government appsUSB Pratirodh and AppSamvid. According to the report, the vulnerabilities found within these two apps can allow hackers to take control of the applications and also execute arbitrary code.
It is important to note that these two apps are aimed at improving device security and preventing cyber attacks on users’ devices.Also, both the apps have been developed by
Affected versions are the IT Ministry’s Centre for Development and Advanced Computing (C-DAC).
Also, if you are unaware, CERT-in is a government body that monitors security flaws, bugs and issues with apps and softwares available across different platforms including Mac, Windows, Android, iOS, Linux, etc and reports them along with the probable cause and solution.
As per the report, the security flaws have been found within the USB Pratirodh version 3.1.2 and prior and AppSamvid version 2.0.1 or older.
Security flaws found in AppSamvid app
CERT-In has reported that two critical vulnerabilities have been found in AppSamvid that could potentially allow attackers to gain unauthorised access and control. The first (CVE-2024-25102) is a sensitive information exposure vulnerability caused by the use of the weaker SHA1 cryptographic algorithm, enabling attackers with local administrative privileges to obtain user passwords.
The second (CVE-2024-25103) is a DLL hijacking vulnerability arising from the use of vulnerable and outdated components, allowing attackers to execute arbitrary code on targeted systems.
These vulnerabilities pose serious risks to the security and integrity of systems running AppSamvid software.
Security flaws found in USB Pratirodh app
USB Pratirodh app has one security flaw that, according to the report, can allow local attackers to take control of the app and also modify the access control of registered users or devices on which the app is installed.
The reason behind the security flaw could be due to the usage of a weaker cryptographic algorithm (hash) SHA1 in the user login component.
What users can do
The government body has advised users to download and install the latest versions of these apps from the respective app stores — Play Store for Andoid and App Store for iPhone and iPads.
That said, updates for both the apps are already available. So, you can download the Upgrade to AppSamvid version 2.0.2 or later and USB Pratirodh version 3.1.3 or later to stay protected from the mentioned security flaws within these apps.





Source link

by Engadget

Walmart is offering its Walmart+ subscription at half off for new sign-ups, and it includes a choice of either Peacock Premium or Paramount+ Essential. The deal for new subscribers is just $49 for the first year, marked down from $98. The real value is in selecting Peacock Premium, which would normally run you $110 per year on its own. With the current discount on a Walmart+ subscription you are essentially getting half off on your streaming subscription for that year. Walmart A Walmart+ subscription is 50… Source link

by CNET

Apple may be developing an iPhone with an under-display camera, and if it’s successful, it will be a remarkable achievement.  A recent rumor from Weibo user Digital Chat Station (translated into English) suggests that such a camera may appear in the 20th anniversary iPhone, which could be called the iPhone 20 and is expected to debut in 2027. The idea of an under-display camera for an iPhone would be novel, but it’s a feature that we’ve seen on several Android phones, with mixed results at best. An… Source link

by Engadget

Snap is offering Snapchat+ subscribers the chance to have 2D Bitmoji avatars once again. In the coming days, they’ll be able to activate a setting called Comic Bitmoji. Snap said this will revive “the charm of classic avatars, while keeping all the benefits of today’s 3D infrastructure.” If you turn on Comic Bitmoji, all Bitmoji avatars that you see in Snapchat will be rendered in 2D. You’ll also be able to send stickers to your friends in that style. Snap switched from 2D to 3D avatars back in… Source link