• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
encryption flaws in popular chinese language app put users' typed

Encryption Flaws in Popular Chinese Language App Put Users’ Typed Data at Risk

You are here: Home / General Cyber Security News / Encryption Flaws in Popular Chinese Language App Put Users’ Typed Data at Risk
August 10, 2023

A widely used Chinese language enter application for Windows and Android has been identified vulnerable to critical security flaws that could enable a malicious interloper to decipher the textual content typed by end users.

The conclusions from the College of Toronto’s Citizen Lab, which carried out an assessment of the encryption mechanism applied in Tencent’s Sogou Input System, an application that has about 455 million regular lively customers across Windows, Android, and iOS.

The vulnerabilities are rooted in EncryptWall, the service’s custom encryption procedure, letting network eavesdroppers to extract the textual material and obtain delicate info.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“The Windows and Android variations of Sogou Input Technique contain vulnerabilities in this encryption procedure, including a vulnerability to a CBC padding oracle attack, which make it possible for network eavesdroppers to get better the plaintext of encrypted network transmissions, revealing delicate data including what buyers have typed,” the scientists explained.

Cybersecurity

CBC, small for cipher block chaining, is a mode of cryptographic procedure in which just about every block of plaintext is XORed with the prior ciphertext block right before being encrypted.

Provided that a block cipher operates on fixed sizing plaintext blocks, a padding oracle attack could be used to leak knowledge about no matter whether the received ciphertext, when decrypted, has a legitimate padding. In accomplishing so, a threat actor could decrypt a concept with out truly knowing the encryption crucial.

Interestingly, the iOS edition of Sogou Enter Technique was observed to be protected against network eavesdropping, whilst it “would have been the most susceptible” thanks to a second defect in the EncryptWall implementation whereby the very first fifty percent of the encryption vital could be trivially recovered.

It can be well worth noting that the scope of the issues are not constrained to Chinese writers in China. Figures from SimilarWeb exhibit that visits to the app’s internet site – shurufa.sogou[.]com – also occur from the U.S., Taiwan, Hong Kong, and Japan.

Cybersecurity

Pursuing responsible disclosure in May well and June 2023, the trouble has been tackled by Tencent in version 13.7 (Windows), 11.26 (Android), and 11.25 (iOS) as of late previous month.

“This vulnerability could have been effortlessly avoided by, alternatively of working with ‘homebrew’ cryptography, adopting TLS, a popular and mature cryptographic protocol with ubiquitous availability and up-to-day assistance,” scientists Jeffrey Knockel, Zoë Reichert, and Mona Wang said.

“While no cryptographic protocol is ideal, TLS implementations had by now ameliorated vulnerability to CBC padding oracle attacks in 2003.”

Discovered this report attention-grabbing? Comply with us on Twitter  and LinkedIn to go through far more distinctive content material we post.


Some elements of this report are sourced from:
thehackernews.com

Previous Post: «cybercriminals increasingly using evilproxy phishing kit to target executives Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives
Next Post: New Statc Stealer Malware Emerges: Your Sensitive Data at Risk new statc stealer malware emerges: your sensitive data at risk»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.