KrebsOnSecurity recently announced that a bug in LocationSmart website was giving out real-time location details of mobile phone customers. It is known that this bug was found out in a free demo tool which is available on the official website of LocationSmart. It revealed the Location details to everybody in general. The customers were of companies such as Verizon, AT&T, Sprint, and T-Mobile.
When KrebsOnSecurity determined that this tool was leaking details without the requirement for any passcode or another mode of authorization or authentication, the tracking firm based in the US took the service offline.
However, LocationSmart verified in an email that Robert Xiao, who is a security researcher at Carnegie Mellon University, was able to get the real-time location of the subscribers only by obtaining their consent personally.