Recently, the hackers managed to bypass the protection of the app store to launch the Fitbit spyware that steals the data from Watch’s face. The security researchers affirmed that the Fitbit markets’ robustness is the trackers, which can control a users’ heart rate, calorie intake, and exercise assemblies, amongst other data.
It is a kind of device that are congenial with a number of apps that can be downloaded from its authentic website and many other app stores; even the customers can also download the watch faces.
We all know that the malware attacks are increasing at a rapid rate, and now according to the reports, attackers are targeting the health-related devices and their data.
Now the question arises here that what could the malicious app do? Accordingly, it could send the following data to the operators behind this spyware:-
But all these data don’t include the PII profile data; here, the calendar invites could reveal all the additional data such as names and locations.
According to the Report, the Fitbit application API reveals access to specific device sensors, such as GPS, heart rate, accelerometer, and body presence.
It also reveals a limited personal API from which we can know the age, height, weight, sex, and average heart rate. However, this API can easily connect to the internet and read all the calendar events if it is synced.
We all know that The Fitbit gallery is a division of the company website that has been specifically designed to display all Fitbit apps and watch faces.
That’s why the security researchers have claimed that it is very easy to publish the malicious watch face to a gallery.fitbit.com URL. As anybody can do so just by using a dashboard that has been used by development teams to study all the apps.
On this matter, Fitbit has replied both politely and promptly. That’s why every security researcher knows all the facts better than many companies. As the experts have affirmed that apps that have been submitted to the Fitbit Gallery for public download must undergo a manual review.
After a proper review, it can get clear that if the spyware or applications are masquerading and are likely to be get caught and be blocked from being issuing. However, this procedure is one of the standard methods, and at the time of writing this report, the ill-disposed watch face was still publicly accessible.
The Fitbit recommended few security measures to all its users, and here they are:-
Moreover, Fitbit said that they believe that the trust of our customers is paramount, and they are committed to protect and guard the consumer privacy and preserving the data safe.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Also Read:
Hackers Installing Spyware on Android Devices That Masquerading as TikTok”Pro”
Beware!! Hackers Launching New Sophisticated Android Spyware “ActionSpy” via phishing Attacks
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…