Reddit
Alipay Vulnerabilities Enable Silent GPS Data Exfiltration via DeepLink Attack
Article Content
A researcher has identified 17 vulnerabilities in Alipay, impacting over 1 billion users. The attack method involves a crafted URL that silently exfiltrates GPS coordinates with high accuracy through a DeepLink, WebView, and JSBridge chain. The vulnerabilities include 6 CVEs submitted to MITRE, with CVSS scores ranging from 7.4 to 9.3. Notably, the attack can capture GPS data without user consent and has been demonstrated across three devices in three different countries. Despite the severity, Alibaba, the parent company, has not assigned CVEs for some vulnerabilities. The vendor claims the functionality is normal, but a takedown complaint was filed four hours after the discovery. The researcher submitted a proof of concept to Reddit.
Key Points: • 17 vulnerabilities found in Alipay, affecting over 1 billion users. • Silent GPS exfiltration achieved via a crafted URL and DeepLink attack chain. • 6 CVEs submitted with high CVSS scores, but Alibaba has not assigned CVEs for all.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.