One Missing Check, Total Exposure: How a Single API Flaw Exposed Every Record Across 3 Apps
One number, changed in a request, returned a different member’s file. Then it let us edit that file, close it, and download the identity documents attached to it. It worked identically from the web app, the iOS app and the Android app, because the check that should have stopped it was missing from the one thing all three of them share - the API underneath.