SEATTLE — Starbucks Corp. said it will soon roll out an update for its iOS mobile application, which a security expert says had a critical flaw that potentially exposed customer data to computer-savvy phone thieves.
Cyber-security researcher Daniel Wood disclosed this week that Starbucks’ digital wallet app for the iPhone doesn’t encrypt critical customer data — including email, password and credit card information. That makes it vulnerable to a hacker or thief who physically takes someone’s iPhone. Starbucks chief information officer Curt Garner, in a letter to customers posted on the company’s website Thursday, acknowledged that Wood’s report highlighted “theoretical vulnerabilities.”
Starbucks maintains that it had already added new barriers to protect the data, though it won’t elaborate for security reasons. The update to the app, Garner wrote, is being readied out of an “abundance of caution” to add extra layers of protection. “We expect this update to be ready soon,” he wrote.
The company has said that the app for Google’s Android mobile operating system doesn’t have the flaw.