Skype iOS App Vulnerability Lets Hackers Steal User Data

 By 
Stan Schroeder
 on 
Skype iOS App Vulnerability Lets Hackers Steal User Data
Mashable Image
Credit:

The cross-site scripting (XSS) vulnerability, demonstrated in the video below, is present in Skype 3.0.1 and earlier versions of Skype's iOS app.

It lets an attacker create malicious JavaScript code that runs when the user views a text message in Skype's chat window. The code can be used to access any file that the Skype app itself has access to, including the address book on your iPhone.

The technical explanation of the bug can be found here.

Skype is aware of the issue and is working on a fix. “We are working hard to fix this reported issue in our next planned release, which we hope to roll out imminently," Skype said in a statement.

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!