Naukri exposed recruiter email addresses, researcher says

Naukri Fixes Bug That Exposed Recruiter Emails on Mobile Apps
Photo: TechCrunch

Naukri Fixes Bug That Exposed Recruiter Emails on Mobile Apps

Naukri.com, one of India’s leading job search platforms, recently resolved a security issue that exposed the email addresses of recruiters using its Android and iOS apps. The flaw, discovered by security researcher Lohith Gowda, was found in the API used by the mobile apps, which inadvertently revealed recruiters’ email addresses to job seekers when they viewed profiles. Notably, the company’s main website was unaffected by this vulnerability.

According to Gowda, the exposed data posed a significant privacy risk, making recruiters susceptible to phishing attacks, spam, and possible inclusion in public data breach databases. Such exposure could also lead to large-scale scraping operations by bots and potential scams.

After TechCrunch independently verified the issue based on Gowda’s findings, Naukri responded promptly and confirmed the bug was fixed earlier in the week. Alok Vij, head of IT infrastructure at InfoEdge, Naukri’s parent company, stated that system enhancements were implemented and no abnormal activity had been detected that might have compromised user data integrity.

Naukri emphasized that certain recruiter profile features are designed to be publicly visible to help job seekers know who views their profiles, but added that the platform undergoes regular audits and security checks. Founded in 1997, Naukri remains a major player in India’s employment services and also operates in the Middle East through Naukrigulf.com.

Leave a Reply

Your email address will not be published. Required fields are marked *