A Skype app vulnerability could expose your IP address to hackers — and Microsoft has yet to fix it

Share via:

Photo by Amelia Holowaty Krales / The Verge

Microsoft is reportedly dragging its feet on fixing yet another security vulnerability. This time, it’s a flaw in the Skype mobile app that could let hackers obtain your IP address by opening a message with a link — no clicking required, according to a report from 404 Media.

The flaw, which was uncovered by the independent security researcher Yossi, allows hackers to see a user’s general location by having them open a message containing a link. While Yossi told Microsoft about the flaw earlier this month, 404 Media reports that the company only promised to issue a patch after the outlet reached out.

To attest to the severity of the flaw, it doesn’t seem to matter what website the link takes you to. The researcher demonstrated the flaw to 404 Media by having its reporter open links to Google.com and 404media.co. Yossi was able to obtain the reporter’s IP address both times — even when they used a virtual private network (VPN), which is supposed to mask your location.

When Yossi reached out to Microsoft about the issue on August 12th, the company reportedly told the researcher that the “disclosure of an IP address is not considered a security vulnerability on it’s [sic] own,” adding that the flaw “does not meet the definition of a security vulnerability” that would “require immediate servicing.”

When 404 Media contacted Microsoft, the company said it would address the flaw in “a future product update” but didn’t provide an estimated timeline. While 404 Media doesn’t provide specifics on how hackers can exploit the flaw, it states that “it is trivially easy to exploit and involves changing a certain parameter related to the link.”

That means hackers can continue exploiting it until Microsoft decides to fix it, potentially exposing users’ information without their knowledge. The Verge reached out to Microsoft with a request for comment and didn’t immediately hear back.

Since Chinese hackers breached US government emails through Microsoft Azure in July, the company has faced growing criticism for its handling of security vulnerabilities. Earlier this month, Amit Yoran, the CEO of the cybersecurity company Tenable, called out the company’s “blatantly negligent” practices while citing his own example of Microsoft delaying a critical fix spotted by the firm. Microsoft only patched the issue after Yoran’s post was published.

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Sarthak Luthra
Sarthak Luthra
Hey, there! I am the tech guy. I get things running around here and I post sometimes. ~ naam toh suna hi hoga, ab kaam bhi dekhlo :-)

Popular

More Like this

A Skype app vulnerability could expose your IP address to hackers — and Microsoft has yet to fix it

Photo by Amelia Holowaty Krales / The Verge

Microsoft is reportedly dragging its feet on fixing yet another security vulnerability. This time, it’s a flaw in the Skype mobile app that could let hackers obtain your IP address by opening a message with a link — no clicking required, according to a report from 404 Media.

The flaw, which was uncovered by the independent security researcher Yossi, allows hackers to see a user’s general location by having them open a message containing a link. While Yossi told Microsoft about the flaw earlier this month, 404 Media reports that the company only promised to issue a patch after the outlet reached out.

To attest to the severity of the flaw, it doesn’t seem to matter what website the link takes you to. The researcher demonstrated the flaw to 404 Media by having its reporter open links to Google.com and 404media.co. Yossi was able to obtain the reporter’s IP address both times — even when they used a virtual private network (VPN), which is supposed to mask your location.

When Yossi reached out to Microsoft about the issue on August 12th, the company reportedly told the researcher that the “disclosure of an IP address is not considered a security vulnerability on it’s [sic] own,” adding that the flaw “does not meet the definition of a security vulnerability” that would “require immediate servicing.”

When 404 Media contacted Microsoft, the company said it would address the flaw in “a future product update” but didn’t provide an estimated timeline. While 404 Media doesn’t provide specifics on how hackers can exploit the flaw, it states that “it is trivially easy to exploit and involves changing a certain parameter related to the link.”

That means hackers can continue exploiting it until Microsoft decides to fix it, potentially exposing users’ information without their knowledge. The Verge reached out to Microsoft with a request for comment and didn’t immediately hear back.

Since Chinese hackers breached US government emails through Microsoft Azure in July, the company has faced growing criticism for its handling of security vulnerabilities. Earlier this month, Amit Yoran, the CEO of the cybersecurity company Tenable, called out the company’s “blatantly negligent” practices while citing his own example of Microsoft delaying a critical fix spotted by the firm. Microsoft only patched the issue after Yoran’s post was published.

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Website Upgradation is going on for any glitch kindly connect at office@startupnews.fyi

Sarthak Luthra
Sarthak Luthra
Hey, there! I am the tech guy. I get things running around here and I post sometimes. ~ naam toh suna hi hoga, ab kaam bhi dekhlo :-)

More like this

Apple Watch Ultra 3: Three new features are coming...

Apple Watch Ultra, outside of a very nice...

From AI avatars to virtual reality crime scenes, courts...

Stacey Wales gripped the lectern, choking back tears...

AI-designed DNA controls genes in healthy mammalian cells for...

A recent study marks the first reported instance...

Popular

Upcoming Events

After Tamil Nadu, Gujarat & UP To Join Electronics...

SUMMARY Following Tamil Nadu announcement of electronics components manufacturing...

How to make Writing Tools on macOS easier to...

One of the few useful Apple Intelligence features...

Anthropic says DOJ proposal in Google search case could...

The US Department of Justice's proposals to increase...
Assista IPTV HD em Portugal com facilidade
Explore os melhores canais IPTV em Portugal
IPTV Portugal – Diversão e qualidade online
Descubra o futuro da televisão com IPTV em Portugal
Serviço IPTV confiável para todos em Portugal
TV online sem complicações com IPTV Portugal
Canais internacionais via IPTV em Portugal
IPTV Portugal – Uma nova forma de ver TV
Viva a experiência IPTV em Portugal agora
IPTV de alta performance disponível em Portugal
Aproveite a TV digital com IPTV Portugal
Transmissão IPTV ao vivo em todo Portugal
IPTV Portugal – Mais canais, mais conteúdo
Assine IPTV em Portugal com um clique
Televisão moderna com IPTV Portugal
Melhore sua TV com IPTV em Portugal
IPTV Portugal – Conteúdo ao seu alcance
Experimente a liberdade da IPTV em Portugal
Navegue pelos melhores canais com IPTV Portugal
A nova era da televisão chegou com IPTV Portugal Assista canais IPTV em Portugal com qualidade garantida
IPTV Portugal – Uma nova forma de ver televisão
Descubra os melhores conteúdos IPTV em Portugal
IPTV em Portugal com transmissão rápida e estável
A melhor experiência de TV online com IPTV Portugal
IPTV Portugal – A escolha inteligente para entretenimento
Veja o que há de melhor em TV digital com IPTV Portugal
Transforme sua sala com IPTV Portugal em minutos
IPTV em Portugal com variedade de canais e filmes
Aproveite IPTV HD sem limites em todo o Portugal
Sintonize os seus canais favoritos com IPTV Portugal
Serviço IPTV confiável e rápido em Portugal
TV online sem complicações com IPTV Portugal
Entretenimento ilimitado com IPTV Portugal
Comece hoje com o melhor IPTV disponível em Portugal
Assista filmes, séries e esportes com IPTV Portugal
IPTV de qualidade para toda a família em Portugal
Mais liberdade de escolha com IPTV Portugal
Veja como IPTV Portugal está a revolucionar a TV
IPTV Portugal – A nova era da televisão digital IPTV Portugal – Televisão moderna ao seu alcance
Desfrute de canais HD com IPTV em Portugal
A revolução digital da TV com IPTV Portugal
IPTV Portugal – A liberdade de assistir quando quiser
Canais internacionais ao vivo com IPTV Portugal
IPTV em Portugal com qualidade e velocidade
Experimente a nova forma de ver TV com IPTV Portugal
IPTV Portugal – Tudo o que precisa para sua TV online
Entretenimento sem limites com IPTV Portugal
IPTV Portugal – Assista onde e quando quiser
IPTV para toda a família em Portugal
Transforme sua televisão com IPTV Portugal
IPTV Portugal – A solução perfeita para sua casa
Veja o melhor da TV online com IPTV Portugal
Comece agora a ver IPTV de forma inteligente em Portugal
IPTV Portugal – Conteúdo sob demanda na sua TV
Comodidade e variedade com IPTV em Portugal
Serviço IPTV acessível e completo em Portugal
Tudo o que quer ver, só com IPTV Portugal
IPTV Portugal – Qualidade e inovação em um só lugar Explore o melhor da TV online com IPTV Portugal
IPTV em Portugal – Canais ao vivo e sob demanda
Assista tudo com qualidade usando IPTV Portugal
IPTV Portugal – Televisão moderna e flexível
Tenha todos os seus canais favoritos com IPTV Portugal
IPTV Portugal – Diversão ilimitada em casa
Transforme a sua forma de ver TV com IPTV Portugal
IPTV Portugal – Qualidade e variedade num só lugar
Desfrute de canais internacionais com IPTV Portugal
IPTV Portugal – Simples de usar, incrível de ver
Assista TV ao vivo e gravada com IPTV Portugal
Mais de 1000 canais com IPTV Portugal – Experimente!
Soluções IPTV ideais para famílias em Portugal
IPTV Portugal – Sem contratos, só entretenimento
Veja o melhor do desporto com IPTV Portugal
IPTV Portugal – TV inteligente com controle total
Canais premium e conteúdo exclusivo com IPTV Portugal
IPTV Portugal – Perfeito para toda a família
A sua nova TV está aqui: IPTV Portugal
Comece hoje mesmo com IPTV Portugal