logo

Chinese Keyboard App Vulnerabilities Explained

ID: 6a2f4893-e4df-5dc5-bd83-42503798762a

STIX ID: report--6a2f4893-e4df-5dc5-bd83-42503798762a

Feed Name: The Citizen Lab

Threat Score
75/100

Date Published: 2024-04-23

Date Updated: 2026-04-19

Author: Jeffrey Knockel

...
...

The report examines cloud-based pinyin keyboard apps used in China and finds that many transmit keystrokes insecurely, enabling ISPs, VPN providers, or other local network eavesdroppers to capture passwords, financial data, and other sensitive input; researchers created working exploits against some vendors (notably Honor and Tencent QQ Pinyin), estimate up to one billion users could be affected, notified vendors, and urge users to update or switch to on-device keyboards (e.g., Gboard, Apple keyboard).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.