logo

Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

ID: 57823162-2972-5b73-956f-bd9c067dae4a

STIX ID: report--57823162-2972-5b73-956f-bd9c067dae4a

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-04-26

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Citizen Lab research found that many popular Chinese Pinyin input method editor (IME) apps—from vendors including Baidu, Samsung, Xiaomi, OPPO, Honor, iFlytek, Tencent and Vivo—use cloud processing or weak/compromised cryptography that can expose users' keystrokes to passive and active eavesdroppers. The flaws and demonstrated exploits affect widely deployed preinstalled keyboard apps representing over 95% market share in China, putting an estimated ~780 million users at risk; patching and update gaps mean the vulnerabilities are likely to persist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.