A vulnerability known as Wormhole affects the Baidu Moplus SDK and potentially exposes more than 100 million Android users to cyber attacks.
The Moplus software development kit (SDK) distributed through Chinese search engine Baidu includes functionality that can be exploited by malicious actors to gain access to a victim's device. The backdoor-like feature potentially exposes over 100 million Android users to cyber attacks.
The Wormhole vulnerability in the Moplus SDK could be exploited by hackers to open an insecure and unauthorized HTTP server connection to the user's device, and this connection occurs in the background without the user's knowledge.
The Moplus SDK automatically installs the Web server when a mobile app developed with the SDK is launched on the device. The server does not perform any authentication and can accept requests from any source. The server accepts requests on both 6259 / 40310 ports, which means that an attacker can easily find open ports on a shared network.
The Moplus SDK is already used in more than 14,000 Android apps, of which about 4,000 are developed by Baidu. These apps have already been downloaded by more than 100 million Android users.
[alert variation=”alert-info”]The Moplus SDK allows an attacker to perform actions such as:
- To send SMS messages
- To make calls
- To receive mobile phone details
- Add new contacts
- Get the list of all local apps
- Download files to the device
- Upload files from the device
- Silently install other apps (if the phone is rooted)
- Push Web pages
- Get information about the device's 'geo-location', and much more.[/alert]



