Jump to content

Genshin Impact: vulnerability allowed to get phone numbers of players


Recommended Posts

Last month, Reddit users revealed that the action-RPG site Genshin Impact did not hide the phone numbers associated with the accounts. However, the media drew attention to this only now.

To find out the player's phone number, it was enough to enter the profile name on the password recovery page. However, the email address where the recovery code will be sent is partially hidden. If a phone number is linked to the account, it was not hidden.

To find out the player's phone number, it was enough to enter the profile name on the password recovery page. However, the email address where the recovery code will be sent is partially hidden. If a phone number is linked to the account, it was not hidden.

This problem was compounded by the fact that players often use the same profile names on different sites. Reddit users tried to enter the profile names of random forum users on the Genshin Impact site and found out their phone numbers.

The developers from the studio miHoYo did not comment on the situation in any way, but they have already fixed the vulnerability.

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.