← Info Edge

2025 Info Edge / Naukri — mobile API flaw exposed recruiter emails when viewing profiles

2025 Unknown records affected Share on X

Data compromised

Recruiter email addresses exposed through predictable API responses

Technical writeup

A reported logical flaw in Naukri's mobile application API let unauthenticated callers harvest recruiter email addresses associated with candidate profile views; Info Edge representatives quoted in TechCrunch confirmed remediation steps after independent disclosure in May 2025 and argued no integrity compromise of broader resume databases in their public response.

Root cause

Insecure direct object reference / authorization gap on mobile API endpoints (per researcher and TechCrunch narrative)

References