Is it true Aarogya setu App got hacked?

An ethical hacker namely Elliot Alderson in his Twitter account stated that privacy of 90 million Arogya Setu app users are at stack. However, he urged to reveal this security flaws only to concerned office only.

Immediately after that Arogya Setu App issued a notice stating that this app fetches location in few cases. A user can see Covid + patients in the radius of 500 m, 1 km, 5 km and 10 km. By using script anyone can change his/her Lat Long of the mobile. So, by changing the lat long one can see Covid + patient at that concerned area.

As a cyber security reviewer I don't see any vulnerable data at stack. This app is to inform people about Covid+ cases in their locality. There is no backdoor as of now to get the users details such as names, id, phone numbers etc. It is more like asking different people about Covid+ cases near his/her location. Same is well explained by Cyber Security expert Jiten Jain in the video provided.


Let's see what else useful data ethical hacker  Elliot Alderson can provide by exploiting this app base. Comment below for any query as well as information regarding this app. You may also inform about the vulnerabilities of Arogya set app in support.aarogyasetu@gov.in.