A popular Android app for finding Wi-Fi hotspots has revealed passwords for over 2 million wireless networks. The program, used by thousands of people, is designed to locate Wi-Fi networks within the device's range. Additionally, users can upload passwords from known hotspots, allowing others to connect to these networks.

It turned out that the database containing millions of Wi-Fi passwords was unprotected. Anyone could download all the information it contained. The unprotected database was discovered by cybersecurity researcher Sanyam Jain. He reported that he had tried to contact the app's developers for more than two weeks to alert them about the issue, but he was unsuccessful. Eventually, the researcher got in touch with the owner of the cloud space where the database was stored. After that, app users were notified about the problem, and the database was taken offline.
It is worth noting that each entry in the database contained data on the exact location of the hotspot, the network name, the service set identifier (BSSID), and the password for connection. The app description states that it can only access public hotspots. In practice, however, it turned out that a significant portion of the database comprised entries about users' home wireless networks.
Source: 3dnews.ru
