Detecting a Skype security vulnerability that can leak user IP addresses
Before the COVID-19 pandemic appeared and somewhat disturbed the market of interactive online services, Microsoft's Skype was one of the dominant solutions in the field of video applications in particular and VoIP calls in general. all around the world. The pandemic appeared and the demand for online interaction exploded, leading to the introduction of a series of new services that made Microsoft's platform gradually lose its position. Of course, Skype still has a significant number of users, with millions of online accounts every day. But a recently discovered security incident could frustrate loyal fans of the service.
Accordingly, a serious vulnerability was recently discovered in Skype that is capable of exposing users' IPs. Successful exploitation of the vulnerability allowed the hacker to obtain the IP address as well as the approximate geographical location of the target. The alarming aspect is that this breach can be accomplished with a simple link sent via the Skype mobile app. Notably, the recipient doesn't even need to interact with the link - just opening the message is enough for an attacker to obtain an IP address. The only 'good news' is that this issue only occurs with the mobile app, not affecting the desktop Skype app at all.
An independent security researcher named Yossi was the first to bring this vulnerability to light and report it to Microsoft. And to our surprise, Microsoft initially downplayed the issue when it received the report, arguing that the IP address disclosure was not fundamentally a critical security hole that needed to be fixed. right away.
After many protests from the user community, as well as security experts and the media, Microsoft seems to have emphasized that exposing IP addresses can lead to privacy violations, potential abuse in personal relationships and even more invasive types of cyberattacks - something the company has always tried to avoid. Microsoft has finally acknowledged the seriousness of the situation and committed to addressing the vulnerability in an upcoming patch.
As of now, the problem has not been resolved. It's only a matter of time before Microsoft releases a fix. However, based on the company's initial response, experts say that this vulnerability is unlikely to have really received a high priority. So for now, if you're using Skype from your smartphone, consider adding a VPN to protect yourself while you wait for an official solution from Microsoft.
You should read it
- Instructions for using IP address 192.168.2.2
- Link this website to friends, you will know their address via the computer's IP
- What is a static IP address?
- Understanding IP address 192.168.1.4
- Increase computer security through DNS server
- How to fix IP 169 address error
- Understanding IP address 192.168.1.3
- What is the IP address 192.168.1.5 used for?
May be interested
- How to prevent Skype applications from running on Windows 10 Background?windows 10 will automatically log in to the user's skype account to make sure that the user always receives incoming messages and calls. however, if you do not want to log in to skype 24/24 every time you open your computer, you can log out and prevent skype from running in the background.
- Critical vulnerabilities discovered in Framework Electron, Skype, Slack, Twitch and a series of affected appsthe framework of a variety of popular desktop applications such as skype, slack, signal, twitch ... appears a serious security hole. it is important that this vulnerability only affects windows.
- Detecting serious security flaws that exist for more than 19 years on WinRAR, can affect 500 million userson february 20, security experts at check point discovered a very dangerous vulnerability that existed inside the library of winrar code over the past 19 years, allowing hackers to broadcast it. a malicious code and plugged into a user's computer to perform malicious purposes.
- Detecting WhatsApp flaws allows an attacker to access files on the machinethis is a cross-site scripting (xss) vulnerability.
- Instructions for changing personal information on Skypewhen you add an email address as well as a phone number, your skype account will be more secure, avoid hacked cases or easily retrieve your account when you lose your password.
- AMD CPUs also have security vulnerabilities that have existed for many years now!another relatively serious vulnerability on amd processors has continued to be discovered, prompting the security community.
- VPN vulnerabilities and how to check and prevent themmost users use virtual private networks (vpns) to encrypt data. but did you know that there are some vpn services that leak sensitive information of users? so what can you do to block vpn leakage? the article will give you some information, how to check and prevent vpn leakage.
- Firefox 16 just got stuck with a serious security bugmozilla must temporarily remove firefox 16.0 final from its website after detecting a serious security vulnerability in this version.
- Warning: Detecting a very serious vulnerability in Cyberoam, a common firewall system in Vietnamvsec is broadcasting a warning about an extremely dangerous vulnerability with the code name cve-2019-17059 on cyberoam.
- How to use Skype web in Firefoxskype in the default web platform is not supported on firefox browsers, but users can use it with very simple tips.