Major Security Flaws Expose Keystrokes of Over 1 Billion Chinese Keyboard App Users
ID: 2fedefdd-26dd-5aee-a4fe-2ad9f502ee7b
STIX ID: report--2fedefdd-26dd-5aee-a4fe-2ad9f502ee7b
Feed Name: The Hacker News
Citizen Lab identified cryptographic and transport-security weaknesses in eight of nine major cloud-based Chinese keyboard/IME apps that can allow network eavesdroppers to recover plaintext keystrokes (via CBC padding oracle, broken/proprietary encryption, or plaintext HTTP). The issues potentially affect up to ~1 billion users across vendors including Baidu, iFlytek, Sogou/Tencent, Samsung, Xiaomi, OPPO, Vivo, and Honor; most vendors have patched the issues except for Honor and Tencent (QQ Pinyin) as of 2024-04-01. Recommendations include using on-device keyboards, standard vetted cryptography, timely patching, and allowing security updates across app stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
