Cyber Security News

Major Security Flaw in Popular Keyboard Apps Puts Millions at Risk

Researchers have uncovered critical security vulnerabilities in several widely used keyboard apps, including those from major tech giants Samsung, OPPO, Vivo, and Xiaomi.

These flaws could allow network eavesdroppers to intercept and decipher every keystroke a user makes, exposing sensitive personal and financial information.

The Citizen Lab’s comprehensive study focused on the security of cloud-based pinyin keyboard apps from nine different vendors.

The analysis included popular brands such as Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi.

Researchers meticulously examined how these apps transmit users’ keystrokes and searched for any vulnerabilities that could be exploited.

Free Webinar | Mastering WAAP/WAF ROI Analysis | Book Your Spot

The findings were alarming: eight of the nine vendors had apps vulnerable to interception.

Keystrokes Capture

This means that an attacker could potentially capture everything a user types, including passwords, credit card numbers, private messages, and more, with relatively minimal effort.

The only vendor whose keyboard app was found without such vulnerabilities was Huawei.

According to The Citizen Lab, the vulnerabilities discovered could affect up to one billion users worldwide, given the popularity of the affected keyboard apps.

VendorApp NameVulnerability DescriptionPotential ImpactUser Base Affected
SamsungSamsung KeyboardUnencrypted data transmissionExposure of all keystrokesHundreds of millions
OPPOOPPO KeyboardWeak encryption methodsEasy interception of typed dataTens of millions
VivoVivo KeyboardNo encryption in certain scenariosDirect access to keystrokesTens of millions
XiaomiXiaomi KeyboardInconsistent encryptionPeriodic exposure of keystrokesHundreds of millions
BaiduBaidu KeyboardUnencrypted data transmissionComplete access to typed informationHundreds of millions
HonorHonor KeyboardWeak encryption methodsPotential decryption of sensitive dataTens of millions
iFlytekiFlytek KeyboardNo encryption for specific data typesExposure of passwords and private messagesMillions
TencentTencent KeyboardInadequate security protocolsInterceptable personal and financial dataHundreds of millions
HuaweiHuawei KeyboardNo vulnerabilities foundN/AN/A

The ease with which these vulnerabilities can be exploited makes it a significant concern, mainly since keyboard apps are used for entering some of the most sensitive information on a device.

The report also highlighted that this is not an isolated issue. Previous analyses have shown similar vulnerabilities in other Chinese apps, and there have been instances where such weaknesses were exploited by intelligence agencies, including those from the Five Eyes alliance.

The vulnerabilities primarily involve the improper or unsecured transmission of keystroke data to cloud servers.

This data transmission, ideally encrypted, appears to be either poorly implemented or completely unencrypted in the cases mentioned, allowing anyone with the right tools and access to the network to intercept the data easily.

In light of these findings, The Citizen Lab has urged all affected companies to address these security flaws promptly.

Users of the implicated keyboard apps are advised to update their apps as soon as patches are available. In the meantime, switching to alternative keyboard apps that prioritize security might be wise.

The report has already prompted responses from several of the companies involved. Samsung, OPPO, Vivo, and Xiaomi have all acknowledged the issue and have announced that they are working on updates to fix the vulnerabilities.

The companies except Baidu, Vivo, and Xiaomi responded to our disclosures,” Citizenlab said.

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago