logo

The not-so-silent type: Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers

ID: f3c48c09-5860-5a47-8ee6-46ad970fbe59

STIX ID: report--f3c48c09-5860-5a47-8ee6-46ad970fbe59

Feed Name: The Citizen Lab

Threat Score
80/100

Date Published: 2024-04-23

Date Updated: 2026-07-17

Author: Jeffrey Knockel

...
...

This report examines cloud-based pinyin IME/keyboard apps from nine major vendors and finds that eight contain transport or cryptographic flaws enabling passive network eavesdroppers to recover users' keystrokes (including passwords and app contexts). The analysis details specific weaknesses (custom AES variants, static/fixed keys, IV reuse, DES/ECB usage, plaintext HTTP/UDP), shows affected platforms and preinstalled OEM builds, estimates up to ~1 billion users potentially impacted, documents vendor disclosure/responses, and offers recommendations to users, developers, OS vendors, and app stores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.