Nvidia store appears to be leaking cached emails to an unspecified number of users (updated)

General
Nvidia store appears to be leaking cached emails to an unspecified number of users (updated)

Update: Nvidia has fixed an error in its web store that occasionally displayed the email address of another user; the following statement has been posted on the GeForce forums.

"Yesterday we received a warning about an issue with the NVIDIA Store order page displaying another customer's email address. We have corrected this issue and reopened the NVIDIA Store the same day. Aside from the incorrect email address being displayed, no customer order or personal information, such as address or payment information, was compromised. We apologize to the affected customers."

Original post PSA for those hoping to get an Nvidia RTX 3000 Series Founder's Edition card: there appears to be a flaw in Nvidia's web store that randomly displays other shoppers' email addresses and other personal information. A Reddit poster published a screenshot of what he claimed was another user's email address and "partially masked" credit card information. Several other posters confirmed that they saw the stranger's email address when they logged in to confirm their order.

The incident appears to be similar to a 2015 cache bug that caused the Steam client to display other users' account information; the Nvidia store, a separate system from the account Nvidia uses for GeForce Experience account, which is specific to the Nvidia Store account. When users try to check the status of their orders, they may see someone else's cached email instead of their own.

On Twitter, TechTeamGB posted an email from one shopper who was contacted by someone who had discovered his email through the Nvidia store. They were asking for his RTX 3080.

I could not reproduce this error myself. I can't find any inventory in the Nvidia store to purchase for the purpose of creating an account at checkout; one of the posters in the reddit thread claims to have "seen several credit cards auto-populate." It is unclear at this time how widespread the problem is or what is causing it, but Nvidia is aware, and the Subreddit community manager said he has "escalated it to our team to investigate."

We contacted Nvidia PR for more information and received the following statement: "We are investigating this issue and will provide further information as it becomes available."

Categories