Skip to content
Search AI Powered

Latest Stories

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

[DIGEST: CNN, The Guardian]

Niantic Labs, the developers of augmented reality game Pokemon Go, made emergency fixes to the game after discovering the app inadvertently had been granted full access to users’ Google accounts. The permissions appeared to affect players who signed up with their Google accounts on Apple devices. According to Google, “full access” means Pokemon Go "can see and modify nearly all information in your Google Account." This includes access to email. Nintendo of America, which owns the Pokemon brand, declined comment. Pokemon Go’s release last Thursday shattered industry records and sent Nintendo’s stock soaring. To date, the game has been downloaded on Android and Apple devices more than 5 million times.


The news sparked fears that playing the game would allow its developers to not only read and send email, but edit and delete documents in Google Drive and Google Photos and access individual browser and map histories. In a statement Monday night, Niantic assured users it only sought minimal information, specifically a user’s unique player ID and email address and that it was working to reduce the user permissions required to play the smartphone game. The company admitted, however, that “the Pokemon Go account creation process on iOS erroneously requests full access."

Credit: Source.

It does not appear Niantic intentionally sought access to users’ personal data––Ingress, Niantic’s other augmented reality game, only requests minimal information from its users––but the company uses an outdated version of Google’s shared sign-on service. This approach is favored by app developers because it makes sign-up quicker and easier for players. It negates the need to create another online account using credentials already stored on their phones. Ideally, shared sign-ons should ask the user what permissions they want to grant the app. In this case, the permission-granting step was skipped because Niantic used an unsupported and out-of-date version of the sign-on process. This error then prompted Google to default to warning users that Pokemon Go had “full access” to their accounts.

It is difficult to ascertain just how much of the blame for the security scare can be apportioned between both parties, but it appears Google may have presented

the limited permissions granted as full access. “Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access,” Niantic said. “Google has verified that no other information has been received or accessed by Pokémon Go or Niantic. Google will soon reduce Pokémon Go’s permission to only the basic profile data that Pokémon Go needs, and users do not need to take any actions themselves.”

Adam Reeve, a computer security expert at cybersecurity firm RedOwl, claimed he discovered the security vulnerability. In a blog post written Monday, Reeve said, "This is probably just the result of epic carelessness. I don't know how well they will guard this awesome new power they've granted themselves... I really wish I could play, it looks like great fun, but there's no way it's worth the risk." Mark Nunnikhoven, a computer security expert with cyber security firm Trend Micro, echoed Reeve’s concerns. "A game shouldn't require this amount of access to your data,” he said.

Credit: Source.

However, fellow cyber security expert and Trail of Bits CEO Dan Guido cast doubt on Reeve’s claim after reaching out to Google tech support. Google assured him that “full account access” does not mean a third party can read or send email, let alone access files. In a statement, Google said that “In this case, we checked that the Full account access permission refers to most of the My account settings. Specific actions such as sending emails, modifying folders, etc, require explicit permissions to that service (the permission will say "Has access to Gmail").” Reeve has since backtracked on his claim, saying he wasn’t “100 percent sure” his blog post was true. Reeve, a former senior engineering manager at Tumblr, admitted he had never built an application that uses Google account permissions and had never tested the claims he makes in his blog post.

More from News

Donald Trump
Kevin Dietsch/Getty Images

Trump Claims The White House Was 'A Sh*t House' When He Moved Back In—And Everyone Had The Same Response

MAGA Republican President Donald Trump has made significant, controversial changes to the White House since he took up residence for his second term on January 20, 2025.

The renovations in just over one year include installing pavers to replace the grass in the Rose Garden, adding gold decor throughout the building and especially in the Oval Office, renovating the Lincoln bathroom to add marble and more gold fixtures, adding gold signs for White House features like it's one of Trump's resorts, hanging a plethora of massive portraits of himself in gaudy gold frames, and demolishing the entire East Wing of the building to erect a self-described monument to himself, an unpopular golden ballroom that will dwarf the rest of the building.

Keep ReadingShow less
Trump Mobile phone; Screenshot of Trump supporter complaining about Trump Mobile
Joe Raedle/Getty Images; @codenamesteev/TikTok

MAGA Melts Down Hard After Learning They May Never Get Their 'Trump Mobile' Phones—Or Their Deposits Back

MAGA fans who signed up to get Trump Mobile T1 phones nearly a year ago are furious after learning there's no guarantee they'll ever get the phones they put down deposits for—and that these same deposits are now being described as merely a "conditional opportunity."

The Trump Mobile T1 phone was unveiled in June 2025 on the 10th anniversary of Trump’s original presidential campaign launch, marking the Trump brand’s debut in the mobile device and wireless service market. At the time, the company said the phone would be available in August.

Keep ReadingShow less
Rep. Alexandria Ocasio-Cortez
UChicago Institute of Politics/YouTube

People Are Applauding AOC's Refreshing Take On Her Political 'Ambition' After She Was Called Out As A 'Likely 2028 Presidential Candidate'

When asked about her future political ambitions during an appearance at the Institute of Politics at the University of Chicago, New York Democratic Representative Alexandria Ocasio-Cortez was notably candid, saying her "ambition is to change this country," as she ripped a Washington Post editorial that tried to knock her down a peg for her take on the morality of billionaires.

The progressive is not currently considered the frontrunner in early 2028 Democratic primary polling but some surveys suggest she has already emerged as a serious contender in what is expected to be a crowded field.

Keep ReadingShow less
Sir Rod Stewart and King Charles III; Donald Trump
Kirsty Wigglesworth - WPA Pool/Getty Images; Kevin Dietsch/Getty Images

Rod Stewart Just Gave Trump The Most Brutally Accurate New Nickname During Candid Conversation With King Charles

On Monday, King Charles III attended an event at Royal Albert Hall to celebrate the 50th anniversary of the King's Trust—previously called the Prince's Trust—which the United Kingdom's reigning monarch founded in 1976 to support young people aged 11-30 facing challenges like unemployment, poverty, or lack of education.

In attendance that night was Sir Rod Stewart, who was knighted in 2016. Stewart and the King have met several times, and briefly chatted while King Charles greeted distinguished guests in the reception line.

Keep ReadingShow less
Chelsea Handler unleashed one of the night’s most brutal roasts on Tony Hinchcliffe during Netflix’s The Roast of Kevin Hart.
Netflix / The Roast of Kevin Hart

Chelsea Handler Destroys MAGA Comedian With Hilariously Brutal Jokes At Kevin Hart's Roast—And We're Cheering

Chelsea Handler brought the heat to Netflix’s The Roast of Kevin Hart Sunday night, and Tony Hinchcliffe ended up taking some of the night’s most brutal hits.

Handler wasted little time zeroing in on Hinchcliffe, the controversial comedian who has repeatedly sparked backlash over jokes about George Floyd and Puerto Rico. She delivered a string of savage punchlines that left the audience roaring while the comic sat visibly unimpressed.

Keep ReadingShow less