These vulnerabilities could allow a network eavesdropper to decrypt sensitive communications sent by the app, including revealing all keystrokes being typed by the user.
Why are these keystrokes being sent over the network to begin with?
A place for all things Cyber Security, from questions, rants, and stories, to the latest attacks, vulnerabilities, and zero days.
These vulnerabilities could allow a network eavesdropper to decrypt sensitive communications sent by the app, including revealing all keystrokes being typed by the user.
Why are these keystrokes being sent over the network to begin with?
For longer strings of syllables, an IME will commonly reach out over the network to a cloud-based service for suggestions if suitable suggestions are not available in the input method’s local database.
This seems particularly dangerous that it's for Chinese users.