TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
  • Login
  • Sign Up
Trending
Starzspins Deutschland: Eine umfassende Übersicht über neue Spiele und ihre Features
Cazeus Casino Chile: guía completa para comenzar a jugar en 2026
Glorion Casino België: ontdek de spannende wereld van live casino spellen
Discover the advantages of using the FunPari O’zbekiston mobile app for instant access to
Rainbet Casino France : débloquez des bonus incroyables en 2026
Sunday, Aug 9, 2026
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards
The Tech Basic > Mobiles > Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards
MobilesNews

Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards

Evelyn Blake
Last updated: 26 April 2024 17:56
Evelyn Blake
Share
SHARE

A survey conducted by CitizenLab revealed concerning findings regarding digital security. When examining the virtual keyboards of nine Chinese companies – Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi – it was discovered that eight of them have a vulnerability. This vulnerability exposes users’ typing data to network spy apps.

Please follow us on Twitter and Facebook.

The information uncovered is potentially hazardous and has the potential to affect over a billion people, according to the organization’s estimates. Users’ typing histories could disclose private information such as access credentials, credit card numbers, and any other sensitive data entered while using the keyboard.

Huawei was the only company analyzed that did not exhibit this vulnerability. However, all eight of the other manufacturers still transmitted typing data on certain products, particularly cloud-based keyboards. These keyboards are linked to specific applications and have the capability to connect to the internet via the cloud.

This situation isn’t entirely novel. Several years ago, Razer disclosed the connectivity of its Synapse app, which comes pre-installed on various accessories, including keyboards. This app allowed users to input commands like “change the color of the RGB lights on my keyboard” via Alexa. Shortly after its launch, a Google security researcher uncovered a loophole in this connectivity, enabling the remote execution of malicious code. Razer swiftly addressed this flaw with a patch released just 24 hours after the news broke.

In CitizenLab’s research, the situation appears to be more alarming. Various types of attacks can exploit these vulnerabilities, and not all keyboards are physical; some are used on Android devices as well. The security organization has compiled a list detailing these potential vulnerabilities:

  • Tencent QQ Pinyin is susceptible to an attack known as “CDC Padding Oracle,” which can retrieve typed data and convert it into text format.
  • Baidu IME contains a bug in the “BAIDUv3.1” protocol, allowing network monitoring apps to decrypt online transmissions on Windows and extract typed text.
  • The iFlytek IME Android app is vulnerable to network monitoring apps, enabling them to decrypt online transmissions and extract typed text.
  • Samsung Keyboard, when used on Android, sends typing data via an unencrypted HTTP protocol.
  • Xiaomi keyboards are vulnerable to the same attacks affecting Baidu, Sogou, and iFlytek, as they are pre-installed on these models.
  • OPPO keyboards are susceptible to the same attacks as Baidu and Sogou, as they come pre-installed on these models.
  • Vivo keyboards are vulnerable to the same attacks as Sogou, as they come pre-installed on these models.
  • Honor keyboards are susceptible to the same attacks as Baidu, as they come pre-installed on these models.

Sogou was not specifically analyzed in this report, but it was identified as a company affected by a similar breach in a previous CitizenLab document.

Samsung, Xiaomi, and Seven Other Companies Have Security Flaws in Their Virtual Keyboards (1)

The situation was further complicated by the challenge of detecting these vulnerabilities. Typically, when a hacker exploits a vulnerability online, there’s often an uptick in data traffic, as the attacker usually needs to send their own data packets. This spike in traffic can be detected by certain security measures.

However, this isn’t the case with these flaws. Because they’re passive, hackers don’t need to generate additional traffic, making it harder to detect their activities—not entirely invisible, but certainly more elusive.

In practical terms, the likelihood of predicting such an attack would be very low. It would likely only become apparent during the attack itself or much later, after the damage has been done.

Most Companies (But Not All) Have Already Fixed the Problem

CitizenLab adhered to ethical protocols for disclosing security flaws by reaching out to the nine companies involved. Despite Huawei not being affected, it was still included in the analysis, and all companies were informed of the issue.

The security organization reported that most companies have already addressed the flaws through update patches released on April 1, 2024. Samsung recently notified users about the update, albeit without directly mentioning the issue. However, Honor and Tencent have yet to respond to contact attempts.

According to the company, it’s theorized that manufacturers may have utilized internally developed encryption mechanisms due to cultural reasons. An excerpt from the report suggests that companies might feel less inclined to adopt protection standards perceived as ‘Western’ due to concerns about their own vulnerabilities.

TAGGED:SamsungXiaomi
Share This Article
Facebook Reddit Copy Link Print
Share
Evelyn Blake
By Evelyn Blake
Follow:
Evelyn Blake is an investor in technology and journalist who has been in the nascent space since 2014. Her love and passion for technological innovations made her delve deeper into the world of technology evolution. As a journalist, Evelyn has been covering latest trends and emerging gadgetries. She is a philanthropist and human rights activist.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

Starzspins Deutschland: Eine umfassende Übersicht über neue Spiele und ihre Features

The Tech Basic

Cazeus Casino Chile: guía completa para comenzar a jugar en 2026

The Tech Basic

Glorion Casino België: ontdek de spannende wereld van live casino spellen

The Tech Basic

Discover the advantages of using the FunPari O’zbekiston mobile app for instant access to

The Tech Basic

You Might Also Like

Galaxy S26
News

Samsung Reinvents AI on Galaxy S26 With Triple Assistants

Gemini
News

Gemini Automation Books Rides on Galaxy S26 and Pixel 10

Galaxy AI
News

Samsung opens Galaxy AI to Perplexity for deeper app workflows

Galaxy S26
News

Samsung Teases Privacy Display for Galaxy S26 With Flex Magic Pixel

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
Microsoft Launches Copilot Tasks Research Preview
Lenovo Teases Foldable Legion Go With 11.6 Inch Screen
Mobile Game Installs Drop but Spending Climbs in 2025
Instagram Will Tell Parents When a Teen Searches for Suicide or Self Harm
Nvidia posts $68.1B quarter as AI boom accelerates Q4 growth

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up