Skip to content
Alipay Vulnerabilities Enable Silent GPS Data Exfiltration via DeepLink Attack

Alipay Vulnerabilities Enable Silent GPS Data Exfiltration via DeepLink Attack

First seen 13 Mar 2026, 17:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 14, 2026 at 17:26 UTC
  • •17 vulnerabilities found in Alipay, affecting over 1 billion users.
  • •Silent GPS exfiltration achieved via a crafted URL and DeepLink attack chain.
  • •6 CVEs submitted with high CVSS scores, but Alibaba has not assigned CVEs for all.

A researcher has identified 17 vulnerabilities in Alipay, impacting over 1 billion users. The attack method involves a crafted URL that silently exfiltrates GPS coordinates with high accuracy through a DeepLink, WebView, and JSBridge chain. The vulnerabilities include 6 CVEs submitted to MITRE, with CVSS scores ranging from 7.4 to 9.3. Notably, the attack can capture GPS data without user consent and has been demonstrated across three devices in three different countries. Despite the severity, Alibaba, the parent company, has not assigned CVEs for some vulnerabilities. The vendor claims the functionality is normal, but a takedown complaint was filed four hours after the discovery. The researcher submitted a proof of concept to Reddit.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2026-03-12
Researcher discovers 17 vulnerabilities in Alipay.
2026-03-12
6 CVEs submitted to MITRE with CVSS scores 7.4-9.3.
2026-03-12
Alibaba refuses to assign CVEs for some vulnerabilities.
2026-03-12
Takedown complaint filed 4 hours after discovery.
2026-03-12
Proof of concept submitted to Reddit.

More articles in this cluster (2)

Following this threat?

Track Alipay in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed