Viber Claims iTunes Flaw To Blame For App Store Account Hack

Messaging app company Viber believes there is a glaring flaw in Apple’s iTunes Connect, which it has blamed for a defacement of its App Store page.

The flaw lets a hacker who is logged in to an iTunes Connect account remain logged in, even when the administrator has removed them from the list of authorised users.

Viber admitted two Viber.com email accounts had been compromised by a phishing attack, allowing the attacker to get the right login details to deface the company’s support site, as TechWeek reported last week, and gain access to its iTunes Connect account.

The defacement of the App Store page was similar to that of the Support site, claiming Viber spied on its users.

Viber attacked

Although Viber removed the user from its iTunes Connect account, the hacker, believed to be a member of the Syrian Electronic Army, remained logged in. And that has left Viber upset.

“On Saturday this happened again. Upon further investigation we realised this is a security issue in iTunes Connect,” a spokesperson said, in an emailed statement sent to TechWeek.

“It seems that when you remove a user, if the user is logged in, then the user stays logged in.

“We hope Apple fixes this issue soon, as currently we have no way to permanently disconnect this user from our iTunes Connect. We have reached out to Apple regarding this issue and are waiting on their response.”

An Apple spokesperson said it had no comment at the time of publication.

“At this point, we want to reassure users, that this has no impact on the security of the Viber App, Viber System, our databases, user information, etc. It’s merely an unfortunate nuisance,” Viber added.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

View Comments

  • Hi,
    I'm an official representative from Viber.

    As mentioned in the article, a security issue in iTunes Connect allowed the same "hackers" who defaced our Support Site to change the description of our AppStore page (and that's all). We have contacted Apple regarding this issue and are awaiting their response. Meanwhile, our AppStore page is back to normal. :)

    We want to reassure our users again: this has no impact on Viber's security. We're safe as always. :)

    Thanks,
    The Viber Team

    • "We are safe as always."

      Viber, you have been hacked. And not only once but twice as it seems. That is exact the opposite of safe, private and secure.

      • Hi Marie,
        Thank you for your comment.

        We wouldn't call this incident "hack". It was a very minor phishing attack that allowed the people behind it to cause superficial damage (change of pages online, and that's it), and it was resolved within minutes in both cases.

        The second case (the AppStore description change) actually has nothing to do with the fact that we (Viber) were hacked.

        You are right, all of the above does not mean that we will ignore the whole incident. We are working hard to ensure that this will not reoccur.

        However, the main point is: at no point was sensitive information taken from anywhere in the company, and that is the most important thing for us to emphasize to our users.

        Thanks again,
        Viber.

Recent Posts

Google, DOJ Closing Arguments Clash Over Search ‘Monopoly’

Google clashes with US Justice Department in closing arguments as government argues Google used illegal…

5 hours ago

Stanford AI Scientist Working On ‘Spatial Intelligence’ Start-Up

Prominent Stanford University AI scientist Fei-Fei Li reportedly completes funding round for start-up based on…

6 hours ago

Apple Shares Surge Ahead Of New AI Hardware Launches

Apple shares surge on optimism that new AI-focused hardware launches will drive renewed sales, starting…

6 hours ago

Biden Vetoes Republican Measure In Row Over Contractors’ Unions

Biden vetoes Republican-backed measure amidst dispute over 'joint employer' status for contract workers, affecting tech…

7 hours ago

Lawyers Say Strict Child Controls In China Show TikTok Could Do Better

Lawyers in US social media addiction action say strict controls on Douyin in China show…

7 hours ago

London Black Cabs Sue Uber In Latest Legal Tangle

More than 10,000 London black cab drivers sue Uber claiming company acted illegally to obtain…

8 hours ago