CVE-2014-5722: Medium severity swiftkey keyboard vulnerability
The SwiftKey Keyboard + Emoji (aka com.touchtype.swiftkey) application 5.0.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5722?
CVE-2014-5722 has a medium severity level due to its ability to allow man-in-the-middle attacks.
How do I fix CVE-2014-5722?
To mitigate CVE-2014-5722, update the SwiftKey Keyboard + Emoji application to the latest version that properly validates SSL certificates.
What systems are affected by CVE-2014-5722?
CVE-2014-5722 specifically affects SwiftKey Keyboard + Emoji version 5.0.2.4 for Android devices.
What type of attack can exploit CVE-2014-5722?
CVE-2014-5722 can be exploited through man-in-the-middle attacks, where attackers spoof SSL servers.
What kind of information is at risk due to CVE-2014-5722?
CVE-2014-5722 allows attackers to obtain sensitive information from users due to improper SSL certificate validation.