Alipay Vulnerabilities Enable Silent GPS Data Exfiltration via DeepLink Attack

Alipay Vulnerabilities Enable Silent GPS Data Exfiltration via DeepLink Attack

First seen 13 Mar 2026, 17:43 UTC Reddit 70.5

Article Content

Browse articles
ThreatCluster

A researcher has identified 17 vulnerabilities in Alipay, impacting over 1 billion users. The attack method involves a crafted URL that silently exfiltrates GPS coordinates with high accuracy through a DeepLink, WebView, and JSBridge chain. The vulnerabilities include 6 CVEs submitted to MITRE, with CVSS scores ranging from 7.4 to 9.3. Notably, the attack can capture GPS data without user consent and has been demonstrated across three devices in three different countries. Despite the severity, Alibaba, the parent company, has not assigned CVEs for some vulnerabilities. The vendor claims the functionality is normal, but a takedown complaint was filed four hours after the discovery. The researcher submitted a proof of concept to Reddit.

Key Points: • 17 vulnerabilities found in Alipay, affecting over 1 billion users. • Silent GPS exfiltration achieved via a crafted URL and DeepLink attack chain. • 6 CVEs submitted with high CVSS scores, but Alibaba has not assigned CVEs for all.

Timeline

2026-03-12
Researcher discovers 17 vulnerabilities in Alipay.
2026-03-12
6 CVEs submitted to MITRE with CVSS scores 7.4-9.3.
2026-03-12
Alibaba refuses to assign CVEs for some vulnerabilities.
2026-03-12
Takedown complaint filed 4 hours after discovery.
2026-03-12
Proof of concept submitted to Reddit.