omi icon indicating copy to clipboard operation
omi copied to clipboard

Security Vulnerability: App Still Has access to my data After Uninstallation

Open skywinder opened this issue 1 year ago • 1 comments

After installing the omi-telebot app to receive Telegram updates about new conversations, I uninstalled it via:
Apps > Filter (Apps) > Installed apps > omi-telebot > Uninstall.

Although the app disappeared from the installed-apps list, I still receive conversation updates in Telegram, indicating it retains access to my data despite uninstallation.

To Reproduce

  1. Install omi-telebot for Telegram notifications.
  2. Confirm that you are receiving updates about new conversations.
  3. Navigate to Apps > Filter > Installed apps in OMI.
  4. Find omi-telebot, click on it, and choose Uninstall app.
  5. Observe that the app disappears from the installed-apps list.
  6. Despite being uninstalled, Telegram updates from omi-telebot continue arriving.

Current behavior

  • Even after uninstalling omi-telebot, I continue receiving conversation updates in Telegram, suggesting that the app still retains access to my data.

Expected behavior

  • Once omi-telebot is uninstalled, it should completely lose access to my OMI data and stop sending notifications to Telegram.

Let me know if additional logs or tests are needed to reproduce this issue!

skywinder avatar Feb 19 '25 19:02 skywinder

@beastoin @kodjima33 Please have a look at this. I believe it’s critical and should be fixed ASAP. Let me know if you need any additional information.

skywinder avatar Feb 25 '25 17:02 skywinder