O2 Privacy Flaw Sends Users' Mobile Numbers to Visited Websites

o2 logoAs noted by think broadband, a privacy flaw in the way UK carrier O2 handles web traffic on mobile devices has resulted in users' mobile numbers being sent to any website visited from the device as part of the headers in the HTTP requests. While O2 is apparently still investigating the situation, it appears to have the potential for significant privacy-related issues.

If you're reading this news article using your O2 mobile phone, you'll be pleased to know that O2 have already sent us your mobile phone number within the HTTP headers which normally contain information about how content can be displayed on your device. These headers are not normally seen by users, and usually not logged by most websites, but the flaw allows malicious sites to get more personal information about you than you may be willing to share.

For example, if you open an e-mail which includes references to external images, the mere action of opening the e-mail would divulge your phone number. This could be used by anyone undertaking a phishing attack or other scam to get more information from you. The opportunity to abuse this is potentially endless.

The issue was discovered by Twitter user @lewispeckover, who then set up a website to allow users to see what headers are being sent as part of their HTTP requests to websites.

He now notes that the headers coming from his device appear to have stopped showing his mobile phone number, although O2 has yet to issue an official statement on the matter. The company's Twitter account is continuing to blast out responses to concerned users, noting only that the company is looking into the situation and will issue an update when it knows more.

The issue is not exclusive to the iPhone and has the potential to affect all mobile data on the second-largest carrier in the UK, although some users have reported that they are not seeing their mobile numbers appearing in their HTTP request headers. The issue has the potential to for a significant impact on UK iPhone users, as O2 has proven to be a popular choice for iPhone users dating back to its status as the exclusive iPhone carrier in the UK when the device originally launched back in 2007.

Those familiar with the UK's privacy laws have indicated that mobile phone numbers are not considered protected information, but the disclosure of such numbers as part of standard HTTP requests does have the potential to carry implications for users.

Popular Stories

App Store vs EU Feature 2

Apple Says It Doesn't Approve of EU Porn App

Monday February 3, 2025 1:15 pm PST by
Apple does not approve of the "Hot Tub" pornography app that was released for the iPhone in the EU using alternative app distribution, Apple said in a statement to MacRumors. Further, Apple is concerned about the potential user safety risks with a pornography app, and says that it undermines consumer trust in the Apple ecosystem. We are deeply concerned about the safety risks that hardcore...
iPhone 17 Pro Dual Tone Horizontal 1

iPhone 17 Pro Launching This Year With These 8 New Features

Tuesday January 28, 2025 11:48 am PST by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. iPhone 17 Pro concept based on rumors Below, we recap key changes rumored for the iPhone 17 Pro models as of January 2025: More aluminum: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models ...
apple power beats pro 2

Apple Expected to Announce Powerbeats Pro 2 on February 11 With These New Features

Sunday February 2, 2025 6:15 am PST by
Apple previously teased that Powerbeats Pro 2 would be released in 2025, and now an announcement date has leaked. Bloomberg's Mark Gurman today said Apple plans to unveil the wireless earbuds on Tuesday, February 11. Powerbeats Pro 2 will be priced at $250 in the U.S., he said. Powerbeats Pro are a sportier, fitness-focused alternative to AirPods Pro with built-in, adjustable ear hooks...
applecare apple care banner

AppleCare+ Policy Change Coming to Apple Stores

Sunday February 2, 2025 8:34 am PST by
Starting next week, Apple's retail stores will no longer offer AppleCare+ plans as a one-time purchase, according to Bloomberg's Mark Gurman. Instead, he said the stores will only offer AppleCare+ as a subscription. For example, AppleCare+ for the iPhone 16 Pro Max costs $9.99 per month, or $199 upfront for two years. The latter option would no longer be available at Apple's stores....
iCloud General Feature Redux

Apple May Launch New iCloud Invite Tool Codenamed 'Confetti' This Week

Sunday February 2, 2025 6:42 am PST by
As early as this week, Apple plans to introduce a new iCloud-based service for event invites, according to Bloomberg's Mark Gurman. In his Power On newsletter, Gurman said the new service is codenamed "Confetti" within Apple. He said the service will offer users a "new way to invite people to parties, functions, and meetings." He did not say if this functionality would be available through a ...
top stories 2025 02 01

Top Stories: iOS 18.3 Released, AirPods News, and More

Saturday February 1, 2025 6:00 am PST by
January has come to a close, with Apple pushing out iOS 18.3 and related software updates in the final week of the month to deliver some refinements for Apple Intelligence, security fixes, and more. We're looking ahead to more substantial updates with iOS 18.4, while we also shared news and rumors about AirPods and the upcoming "iPhone 17 Air," so read on below for all the details! iOS...
maxresdefault

The MacRumors Show: Latest iPhone SE 4 Rumors

Friday January 31, 2025 8:29 am PST by
On this week's episode of The MacRumors Show, we talk through all of the latest rumors about the iPhone SE 4 as it nears launch. Subscribe to The MacRumors Show YouTube channel for more videos The fourth-generation iPhone SE is widely rumored to feature an iPhone 14-style all-screen design with a 6.1-inch OLED display, Face ID, and USB-C. Images of dummy models showcasing the new design were ...

Top Rated Comments

Elijahg Avatar
170 months ago
I've really not been impressed by O2 in recent years. I first joined them in 2006, but ever since then, their network coverage in the 20 mile radius of here (near Bath) hasn't improved one bit. The 3G coverage is absolutely awful. If you aren't in a major town or a city, you have no chance of 3G with O2, only dial-up speed GPRS. Not even EDGE in most cases.

Everything Everywhere are very good, but Three (in the south of England at least) are best by far for 3G coverage.

Perhaps if O2 spent more money on, well, being a service provider and improving their network, rather than all that "priority moments" crap, they might increase their 3G coverage.
Score: 6 Votes (Like | Disagree)
Elijahg Avatar
170 months ago
Not so in my o2 account with an iPhone using iOS 5.0.1 via Safari.

It wasn't inserted into the user agent, it was a separate header: "x-up-calling-line-id".
Score: 4 Votes (Like | Disagree)
japanime Avatar
170 months ago
The "O" is for "Oops!"
Score: 4 Votes (Like | Disagree)
0098386 Avatar
170 months ago
I'm appalled they let this in.

I'm thrilled they fixed it so quickly.

I'm going to treat o2 with a bit more suspicion from here on out.
Score: 2 Votes (Like | Disagree)
The Phazer Avatar
170 months ago
I am now intrigued though as to who the "trusted partners" are. O2 themselves and BT Openzone are the only ones I can think of.

One is Bango, the company that runs O2's adult verification software and thought sending credit card numbers in plaintext over http was a good idea.

O2 might "trust" them. I don't.

Phazer
Score: 2 Votes (Like | Disagree)
4D4M Avatar
170 months ago
I'm perfectly happy with O2, I've found the coverage decent and I don't get loads of junk text messages from them like I did from Vodafone*. This latest gaffe is a bit annoying, but whatever, as a business owner my details are well and truly 'out there' for all the lowlife to exploit anyway. Bring it on scumbags.

*The junk texts don't stop when you leave Vodafone. The other day I received a text that said "Come back to Vodafone and we'll give you a free Windows 7 laptop". If there's one thing that would be guaranteed to STOP me going back to them, it's the threat of a crappy low end piece of junk with a crappy low end OS turning up at my house.
Score: 2 Votes (Like | Disagree)