More than a billion users may be at risk due to a security flaw in the keyboard tracking app

Nearly a billion mobile users, who owned multiple devices, could have had their communications exposed to malicious third parties, claims a report by cybersecurity researchers Citizen Lab.

It says that different device makers have used different keyboard apps that passed unencrypted communications, conveyed keystrokes via plain text and the like. Tencent QQ Pinyin, Baidu IME, iFlytek IME, Samsung Keyboard on Android, Xiaomi (with keyboard apps from Baidu, iFlytek and Sogou), OPPO, Vivo, Honor, all these allowed potential threat actors to decode the keystrokes of Chinese mobile users , completely passive, and without users having to send additional network traffic.