TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
PlayStation Stars Program Ends Sony Promises New Loyalty Plans
Google’s AI Agents Now Handle Tasks While You Relax
Meta offers cash and expert help to startups building with Llama AI
OpenAI Bets Big on Hardware With Acquisition of Jony Ive’s Startup
Play Pitfall and MechWarrior on Game Pass’s New Retro Library
Friday, May 23, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards
The Tech Basic > Mobiles > Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards
MobilesNews

Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards

Evelyn Blake
Last updated: 26 April 2024 17:56
Evelyn Blake
Share
SHARE

A survey conducted by CitizenLab revealed concerning findings regarding digital security. When examining the virtual keyboards of nine Chinese companies – Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi – it was discovered that eight of them have a vulnerability. This vulnerability exposes users’ typing data to network spy apps.

Please follow us on Twitter and Facebook.

The information uncovered is potentially hazardous and has the potential to affect over a billion people, according to the organization’s estimates. Users’ typing histories could disclose private information such as access credentials, credit card numbers, and any other sensitive data entered while using the keyboard.

Huawei was the only company analyzed that did not exhibit this vulnerability. However, all eight of the other manufacturers still transmitted typing data on certain products, particularly cloud-based keyboards. These keyboards are linked to specific applications and have the capability to connect to the internet via the cloud.

This situation isn’t entirely novel. Several years ago, Razer disclosed the connectivity of its Synapse app, which comes pre-installed on various accessories, including keyboards. This app allowed users to input commands like “change the color of the RGB lights on my keyboard” via Alexa. Shortly after its launch, a Google security researcher uncovered a loophole in this connectivity, enabling the remote execution of malicious code. Razer swiftly addressed this flaw with a patch released just 24 hours after the news broke.

In CitizenLab’s research, the situation appears to be more alarming. Various types of attacks can exploit these vulnerabilities, and not all keyboards are physical; some are used on Android devices as well. The security organization has compiled a list detailing these potential vulnerabilities:

  • Tencent QQ Pinyin is susceptible to an attack known as “CDC Padding Oracle,” which can retrieve typed data and convert it into text format.
  • Baidu IME contains a bug in the “BAIDUv3.1” protocol, allowing network monitoring apps to decrypt online transmissions on Windows and extract typed text.
  • The iFlytek IME Android app is vulnerable to network monitoring apps, enabling them to decrypt online transmissions and extract typed text.
  • Samsung Keyboard, when used on Android, sends typing data via an unencrypted HTTP protocol.
  • Xiaomi keyboards are vulnerable to the same attacks affecting Baidu, Sogou, and iFlytek, as they are pre-installed on these models.
  • OPPO keyboards are susceptible to the same attacks as Baidu and Sogou, as they come pre-installed on these models.
  • Vivo keyboards are vulnerable to the same attacks as Sogou, as they come pre-installed on these models.
  • Honor keyboards are susceptible to the same attacks as Baidu, as they come pre-installed on these models.

Sogou was not specifically analyzed in this report, but it was identified as a company affected by a similar breach in a previous CitizenLab document.

Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards (1)

The situation was further complicated by the challenge of detecting these vulnerabilities. Typically, when a hacker exploits a vulnerability online, there’s often an uptick in data traffic, as the attacker usually needs to send their own data packets. This spike in traffic can be detected by certain security measures.

However, this isn’t the case with these flaws. Because they’re passive, hackers don’t need to generate additional traffic, making it harder to detect their activities—not entirely invisible, but certainly more elusive.

In practical terms, the likelihood of predicting such an attack would be very low. It would likely only become apparent during the attack itself or much later, after the damage has been done.

Most Companies (But Not All) Have Already Fixed the Problem

CitizenLab adhered to ethical protocols for disclosing security flaws by reaching out to the nine companies involved. Despite Huawei not being affected, it was still included in the analysis, and all companies were informed of the issue.

The security organization reported that most companies have already addressed the flaws through update patches released on April 1, 2024. Samsung recently notified users about the update, albeit without directly mentioning the issue. However, Honor and Tencent have yet to respond to contact attempts.

According to the company, it’s theorized that manufacturers may have utilized internally developed encryption mechanisms due to cultural reasons. An excerpt from the report suggests that companies might feel less inclined to adopt protection standards perceived as ‘Western’ due to concerns about their own vulnerabilities.

TAGGED:SamsungXiaomi
Share This Article
Facebook Reddit Copy Link Print
Share
Evelyn Blake
By Evelyn Blake
Follow:
Evelyn Blake is an investor in technology and journalist who has been in the nascent space since 2014. Her love and passion for technological innovations made her delve deeper into the world of technology evolution. As a journalist, Evelyn has been covering latest trends and emerging gadgetries. She is a philanthropist and human rights activist.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

PlayStation Stars

PlayStation Stars Program Ends Sony Promises New Loyalty Plans

S.Dyema Zandria
Google AI

Google’s AI Agents Now Handle Tasks While You Relax

S.Dyema Zandria
Meta

Meta offers cash and expert help to startups building with Llama AI

S.Dyema Zandria
OpenAI

OpenAI Bets Big on Hardware With Acquisition of Jony Ive’s Startup

S.Dyema Zandria

You Might Also Like

Apple
News

Samsung’s Breakthrough Display Tech Powers Apple’s Upcoming iPhone Fold

Samsung
MobilesNews

Samsung’s New Foldable Phones Get Bigger Batteries and Better Cameras

Perplexity AI
Blog

Perplexity AI Challenges Google with Samsung and Motorola Partnerships

Samsung One UI 7
News

Samsung Stops One UI 7 Update After Phones Get Stuck

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
Play Pitfall and MechWarrior on Game Pass’s New Retro Library
iPhone 7 Plus and iPhone 8 Now Declared Vintage by Apple
Google AI Mode Launches in US with Easy Search and Shopping Tools
PlayStation Plus Subscribers Lose Six Popular Titles in June 2025 Update
Fortnite Is Back on iPhone App Store with New Star Wars Season

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?