HomeSecurityCritical vulnerabilities in top Android VPN apps allow data theft

Critical vulnerabilities in top Android VPN apps allow data theft

Security researchers have discovered critical vulnerabilities in top VPN apps offered for free for Android devices . The vulnerabilities allow attackers to perform Man-in-the-Middle attacks and steal sensitive user data

Android VPN
Critical vulnerabilities in top Android VPN apps allow data theft

There are many dangerous VPN apps that have been installed on more than 120 million devices. The free VPN, called SuperVPN, has been installed on at least 100 million Android devices.

This particular VPN application is used by users in 150 countries.

SuperVPN is designed by SuperSoftTech, a company based in Singapore. However, it is actually owned by independent app publisher Jinrong Zheng, from China.

Unencrypted communications

Security researchers examined SuperVPN and found that sensitive encrypted data over insecure HTTP.

Also, the VPN application contains a decryption key that allowed researchers to decrypt the data.

This leads to the discovery of sensitive data about the server , its certificates, and the credentials that the VPN server needs for authentication.

Attackers can use this information and replace the real SuperVPN server data with fake server data.

The severity of vulnerabilities

According to experts, attackers can exploit vulnerabilities in VPNs and monitor users' communications and activities . In this way, they can gain access to sensitive data, such as the sites users visit . In addition, they can steal usernames and passwords, photos, videos, messages and more.

Critical vulnerabilities in top Android VPN apps allow data theft
Critical vulnerabilities in top Android VPN apps allow data theft

According to the researchers, “some applications have their encryption keys inside the VPN application. This means that even if the data is encrypted, hackers can easily decrypt using these keys.”

Developers of VPN applications left some of the keys behind, helping attackers gain easy access to users' encrypted data.

“In 2016, SuperVPN had only 10,000 downloads. Now, it has more than 100 million. Even though many articles said that SuperVPN was malicious, it has not yet been removed from the Play Store,” the researchers said.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS