Menu
Alibaba's UC Browser found leaking users' data

Alibaba's UC Browser found leaking users' data

Alibaba claims it has fixed the issues

The UC Browser is a popular app in China. Alibaba Group acquired it last year.

The UC Browser is a popular app in China. Alibaba Group acquired it last year.

A mobile browser owned by China's Alibaba Group contained privacy risks that could have exposed users' personal data, according to a security group.

The flaws were found in UC Browser, a third-party app that's been expanding in popularity across the globe, and has over 100 million daily active users. Last year, Chinese e-commerce giant Alibaba Group acquired UC Browser's parent company.

The Citizen Lab at the University of Toronto's Munk School of Global Affairs investigated the mobile browser, and found that it was sending user data unencrypted, or with not enough encryption. This included transmitting phone numbers and device serial numbers, in addition to user search queries and geolocation data.

The lack of encryption would let anyone with access to the data traffic to identify a user's phone number, the device, and the person's location, Citizen Lab said in its report released Thursday.

Both UC Browser's Chinese language and English language versions contained the reported flaws. On Friday, Alibaba said it investigated the issues and has fixed the problem with a version update users can now download. "We have no evidence that any user information has been taken," the company said in an email.

The privacy risk is that governments such as China and India often require telecommunication providers to hand over their data traffic, Citizen Lab said. Any personal data leaked through UC Browser could be used by governments or other third parties, it added.

Citizen Lab investigated the UC Browser after a leak of a 2012 document by Edward Snowden, disclosed by Canada's CBC News, showed that Canada's intelligence agency and its partners were allegedly aware of security flaws in UC Browser, and wished to exploit them for electronic surveillance.

Although Citizen Lab found problems with UC Browser's software, the group could not confirm if they were the same vulnerabilities detailed in the document disclosed by the former National Security Agency contractor.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags privacymobilemobile applicationsAlibaba Group

Featured

Slideshows

Reseller News welcomes industry figures for 2019 Hall of Fame lunch

Reseller News welcomes industry figures for 2019 Hall of Fame lunch

Reseller News welcomed 2018 inductees - Chris Simpson, Kendra Ross and Phill Patton - to the third running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing landscape of the technology industry in New Zealand, while outlining ways to attract a new breed of players to the ecosystem. Photos by Gino Demeer.

Reseller News welcomes industry figures for 2019 Hall of Fame lunch
Upcoming tech talent share insights at inaugural Emerging Leaders Forum 2019

Upcoming tech talent share insights at inaugural Emerging Leaders Forum 2019

The channel came together for the inaugural Reseller News Emerging Leaders Forum in New Zealand, created to provide a program that identifies, educates and showcases the upcoming talent of the ICT industry. Hosted as a half day event, attendees heard from industry champions as keynoters and panelists talked about future opportunities and leadership paths and joined mentoring sessions with members of the ICT industry Hall of Fame. The forum concluded with 30 Under 30 Tech Awards across areas of Sales, Entrepreneur, Marketing, Management, Technical and Human Resources. Photos by Gino Demeer.

Upcoming tech talent share insights at inaugural Emerging Leaders Forum 2019
Show Comments