Cyber Security News

Microsoft Store App Vibing.exe Allegedly Harvested Screens, Audio, and Clipboard Content

A suspicious executable named Vibing.exe on the Microsoft Store has sparked major privacy and security alarms among cybersecurity researchers.

Marketed as an interface to the “AI-native world” by the elusive Vibing-Team, the application reportedly harvests sensitive user data without explicit consent.

According to Kevin Beaumont, once installed on a Windows endpoint, Vibing configures itself to launch automatically upon login.

The application aggressively monitors user activity and transmits telemetry to a preconfigured Azure Front Door endpoint.

It utilizes WebSockets for communication, a known method for bypassing certain proxy blocking configurations.

The application covertly captures several types of sensitive user data:

  • Base64-encoded screenshots of the user’s active desktop.
  • Raw audio recordings captured directly from the system microphone.
  • Hijacked the clipboard contents containing copied text and files.
  • Specific keywords, window titles, and active application names.

Every piece of transmitted data is tagged with a unique hardware GUID.

This identifier allows the developers to track individual users and link screenshots to specific machines over time.

This highly invasive tracking practice is completely omitted from the application’s user interface and documentation.

Although presented as an open-source tool built by the community, OSINT investigations reveal the application is directly tied to Microsoft GenAI research labs in Beijing.

The official GitHub repository for Vibing contains no actual source code; it merely hosts an 80MB binary file.

This executable is digitally signed by Microsoft researcher Yaoyao Chang using an SSL.com co-signer.

The change describes the adoption as “open-source” (Source: Medium)

Key evidence tying this alleged community project back to Microsoft includes:

  • The Azure endpoint that receives the harvested data belongs to a Microsoft corporate-owned tenant.
  • Initial mentions of Vibing appeared directly on Microsoft’s official VibeVoice GitHub page.
  • Installation documentation features screenshots taken from authenticated Microsoft corporate devices.
  • The project uses the same logo as Microsoft’s official VibeVoice product.

Privacy and Security Implications

By masquerading as a community-driven initiative, the developers appear to have bypassed Microsoft’s rigorous internal governance, privacy, and security review processes.

According to researcher Kevin Beaumont on DoublePulsar, the application exposes a massive attack surface and operates with troubling opacity.

Security teams and administrators should note several critical privacy violations:

  • The Microsoft Store privacy policy falsely claims that no data is sent to third parties.
  • Users receive no in-app prompts or consent requests before audio and screen transmission begins.
  • There is no designated data controller, and there is no transparency regarding data retention policies.
  • Tracking keystrokes and screenshots via hardware GUIDs creates severe long-term surveillance risks.

Despite mounting pressure from the developer community, Microsoft has yet to issue a formal response.

Developers have tagged the involved Microsoft employees on GitHub to highlight the covert data collection.

However, individuals associated with the project have either ignored the tags or abruptly closed the issues, leaving the security community without answers.

Threat hunters and security teams should monitor their environments for the following indicators associated with this software: vibing.exe, Vibing Installer.exe, vibing-api-ccegdhbrg2d6bsd7.b02.azurefd.net

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

5 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

9 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

15 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

20 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

31 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago