Hackers can now capture your IP address and expose your physical location by sending a Skype link, even if you don’t click it.
An IP address, which stands for “Internet Protocol address,” is like a unique digital home address for your device on the internet.
The IP addresses are sensitive addresses because they can reveal certain information about you and your online activities like:-
In a report shared with 404 Media, it’s been affirmed that the cybersecurity researcher behind this discovery, Yossi, has already notified Microsoft about this vulnerability earlier this month.
After being notified by Yossi, Microsoft initially ignored fixing this vulnerability until 404 Media pushed Microsoft for a patch.
With DoControl, you can keep your SaaS applications and data safe and secure by creating workflows tailored to your needs. It’s an easy and efficient way to identify and manage risks. You can mitigate the risk and exposure of your organization’s SaaS applications in just a few simple steps.
An IP reveals location, especially in less populated areas, due to which this attack potentially threatens the following entities:-
Cooper Quintin, a security researcher and senior public interest technologist at the activist organization the Electronic Frontier Foundation (EFF), verified the vulnerability with a practical demonstration from Yossi.
In the practical demo with Cooper Quintin, Yossi sent a legit link on Skype to Cooper, and without clicking on it, the IP address of Cooper Quintin got exposed.
Moreover, Yossi stated that the IP address issue only affected Skype’s mobile apps, not the Mac version.
In normal chats, apps act as buffers between users, often holding IP info. However, in the case of Skype, it seems unusual, as it shares the IPs if hacked, and this could risk the privacy of pseudonymous dissidents.
It’s been justified that the exploitation of this vulnerability is quite simple, as it involves tweaking a certain link parameter.
For now, 404 Media affirmed that they will not disclose any technical details regarding this vulnerability since Microsoft has not yet fixed this flaw.
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…
CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building…
A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin, formerly…