Chinese Keyboard Apps Open 1B People to Eavesdropping
ID: b4a81c93-a308-575a-a8d5-c2490f3a5cb3
STIX ID: report--b4a81c93-a308-575a-a8d5-c2490f3a5cb3
Feed Name: Dark Reading
Citizen Lab identified exploitable vulnerabilities across multiple cloud-based Chinese Pinyin keyboard apps (from vendors including Baidu, Tencent, iFlytek, Samsung, Xiaomi, OPPO, Vivo, Honor) that can expose entire keystrokes to passive network eavesdroppers. The report documents apps sending keystrokes in the clear or using insufficient encryption, researcher-developed working exploits for several products, and estimates that hundreds of millions (up to ~1 billion) users may be affected, enabling large-scale surveillance and credential/financial data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
