• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Anne Hathaway says she was spammed with ChatGPT-written thank you notes after hiring for a recent role: ‘Nobody on that list gets that job’

2

Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it

3

The affordability crisis is so bad that, for the first time ever, both mom and dad are working full-time in most American families

1

Anne Hathaway says she was spammed with ChatGPT-written thank you notes after hiring for a recent role: ‘Nobody on that list gets that job’

2

Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it

3

The affordability crisis is so bad that, for the first time ever, both mom and dad are working full-time in most American families
Tech

A Security Flaw in a Free Web Service Let Anyone Anonymously Track U.S. Cell Phones

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
May 19, 2018, 12:42 PM ET
Add Fortune on Google for similar content.

A bug in the free demo version of a service called LocationSmart made it easy for a moderately savvy attacker to anonymously track the location of nearly any U.S. cell phone, before the bug was identified by a security researcher. The flawed tracking portal has since been shuttered, but the incident is a scary reminder that cell phones can be a major risk to personal security and privacy.

LocationSmart allows location tracking of phones on networks including AT&T, Sprint, T-Mobile, and Verizon. It normally requires that a phone’s owner consent to being tracked, and the company markets its service primarily to companies who want to keep track of their own workers, resources, or consenting customers.

But this week Robert Xiao, a PhD candidate at Carnegie Mellon University, told the security site KrebsOnSecurity that he had discovered a huge flaw in a demo tool that LocationSmart provided to potential customers. While the demo tool was supposed to require consent from the user being tracked, Xiao told KrebsOnSecurity that with “minimal effort” the tool could be used to “track most peoples’ cell phone without their consent.”

Get Data Sheet, Fortune’s technology newsletter.

Xiao and Krebs tested the exploit on several cell phone users, including one in Canada. In addition to finding the phones’ location to within 100 yards without the targets’ consent, the data could be plugged into Google Maps to determine the tracked phone’s direction of movement. (The tests were performed only after targets gave permission outside of the LocationSmart system). The exploit, which reportedly hinged on an insecure API feature, did not require that an attacker provide any of their own identity information.

In response to the report, LocationSmart issued a statement Friday saying that it has “resolved” the vulnerability and disabled the exploitable demo. The company also claims “the vulnerability was not exploited prior to May 16th and did not result in any customer information being obtained without their permission.”

The flaw was discovered, though, following reports that connected LocationSmart to another scary cell-tracking incident. On May 10th, the New York Times reported that a former Missouri sheriff had used a service provided by Securus Technologies to track the locations of private citizens without a court order. ZDNet then discovered that Securus was getting its data from LocationSmart.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Both U.S. and Chinese AI firms are setting up shop in Singapore. Can the country become Asia’s neutral AI hub?
AsiaSingapore
Both U.S. and Chinese AI firms are setting up shop in Singapore. Can the country become Asia’s neutral AI hub?
By Angelica AngJune 19, 2026
3 hours ago
Exclusive: Azzi Fudd joins Project B, the international league chasing a billion-dollar opportunity in global basketball
MPWSports
Exclusive: Azzi Fudd joins Project B, the international league chasing a billion-dollar opportunity in global basketball
By Emma HinchliffeJune 19, 2026
10 hours ago
g
CommentaryVenture Capital
I watched enterprises buy AI that solved the wrong problem. So I left Dell and built a startup to fix it
By Ganesh PadmanabhanJune 19, 2026
11 hours ago
Sam Altman looks down and to the side, frowning.
AIOpenAI
Sam Altman was ‘0%’ excited to be a CEO of a public company—but OpenAI is taking steps to compete in the AI IPO blitz anyway
By Sasha RogelbergJune 19, 2026
12 hours ago
Record revenues. Record profits. Record revenue per employee. The Fortune 500 is richer than ever—and employing fewer people
EconomyFortune 500
Record revenues. Record profits. Record revenue per employee. The Fortune 500 is richer than ever—and employing fewer people
By Claire ZillmanJune 19, 2026
12 hours ago
Samantha Gloede
CommentaryLeadership
Boards must avoid sleepwalking into the AI era. KPMG’s Global AI risk chief has a survival guide
By Samantha GloedeJune 19, 2026
12 hours ago

Most Popular

Anne Hathaway says she was spammed with ChatGPT-written thank you notes after hiring for a recent role: ‘Nobody on that list gets that job’
Success
Anne Hathaway says she was spammed with ChatGPT-written thank you notes after hiring for a recent role: ‘Nobody on that list gets that job’
By Orianna Rosa RoyleJune 18, 2026
2 days ago
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
Environment
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
By Sydney LakeJune 19, 2026
12 hours ago
The affordability crisis is so bad that, for the first time ever, both mom and dad are working full-time in most American families
Economy
The affordability crisis is so bad that, for the first time ever, both mom and dad are working full-time in most American families
By Jacqueline MunisJune 17, 2026
2 days ago
Current price of oil as of June 18, 2026
Personal Finance
Current price of oil as of June 18, 2026
By Joseph HostetlerJune 18, 2026
1 day ago
Hundreds of Stanford students walked out of their grad ceremony to protest Google CEO’s commencement speech. It wasn’t all about AI
Big Tech
Hundreds of Stanford students walked out of their grad ceremony to protest Google CEO’s commencement speech. It wasn’t all about AI
By Tristan BoveJune 15, 2026
4 days ago
Microsoft boss Steve Ballmer publicly dismissed Chrome as a 'rounding error'—but Google’s CEO says he used the jab as fuel to win the browser-wars
Success
Microsoft boss Steve Ballmer publicly dismissed Chrome as a 'rounding error'—but Google’s CEO says he used the jab as fuel to win the browser-wars
By Preston ForeJune 17, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.