Urgent.News

What's breaking now, across thousands of outlets.

Science

Security boffin claims airport group left API keys in client-side JavaScript for four years

Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion

Security boffin claims airport group left API keys in client-side JavaScript for four years

Security researcher Scott Helme has found that Manchester Airports Group (MAG) left privileged API keys exposed in client-side JavaScript for four years. The keys, belonging to Iterable, a marketing automation platform, were exposed in front-end JavaScript served by MAG's websites for Manchester, Stansted, and East Midlands airports.

Helme discovered the keys by using the Internet Archive's Wayback Machine to examine older versions of the JavaScript. The keys were first introduced in June and July 2022 and remained exposed until August 2026. Anyone who accessed the page source during this period could have obtained the keys. Helme noted that the API keys were used to authorize server-side API operations, which should have occurred through MAG's servers instead.

The keys had overprivileged access to core Iterable endpoints, allowing anyone who obtained them to access sensitive data and perform actions like deleting customer records and rewriting profiles. MAG described the incident as sophisticated and claimed it was a hack, not a lapse. However, Helme believes that any hacker with access to the publicly available data could have exploited the vulnerability.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Science

More from Wednesday 9 September →