Hotspot Shield VPN Can Leak Users' Information to Hackers, Fix Incoming

Advertisement
By Jagmeet Singh | Updated: 7 February 2018 11:30 IST
Highlights
  • Hotspot Shield found to have a serious vulnerability
  • The flaw could let attackers extract sensitive information
  • AnchorFree has promised an update to patch the vulnerability

A Virtual Private Network (VPN) is the need of the hour if you want to hide your identity on the Internet. But in a fresh discovery, a security researcher has found that users opting Hotspot Shield, which claims to have over 500 million users worldwide, are at risk as the VPN client is disclosing their sensitive information.

The vulnerability, listed as CVE-2018-6460 on the National Vulnerability Database in the US, lets attackers extract details about the system on which Hotspot Shield is running; moreover, the hackers can figure out whether the user is connected to the VPN and from which location courtesy the bug. AnchorFree, the company behind Hotspot Shield, has reportedly acknowledged the flaw to an extent and promised an update to protect its users.

Web application security researcher and penetration tester Paulos Yibelo, who spotted the Hotspot Shield bug, revealed the VPN client hosts sensitive JSONP endpoints on its native Web server that return various values and configuration data. All this could help a potential attacker to obtain sensitive information secretly. "User-controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address," reads the description of the vulnerability.

Advertisement

Folks at ZDNet were able to verify the presence of the vulnerability by using the proof-of-concept code developed by Yibelo. The proof-of-concept code calls from a JavaScript file hosted on Hotspot Shield's web server that is installed on the user's computer to return sensitive data, including configuration details of the machine.

While Yibelo claims that he was able to obtain real IP addresses of a Hotspot Shield user in some cases, ZDNet didn't find them during their tests. AnchorFree VP of Marketing Communications Tim Tsoriev also reportedly denied Yibelo's claim regarding the exposed IP addressed, and stated that the vulnerability neither leaks real IP addresses of users nor any personal information. That being said, Tsoriev, in a statement to ZDNet, did mention that the vulnerability "may expose some generic information" and could let attackers see the user's country. The executive also asserted that an update to fix the serious flaw will be released this week.

Interestingly, AnchorFree was aware of the vulnerability exists within Hotspot Shield since December, but it didn't respond to Yibelo's finding at that time. The VPN client claims to to encrypt user data, including passwords, financial transactions, and instant messages and can detect and block more than 3.5 million malicious, phishing, and spam sites. Moreover, it offers a US IP address to mask the actual IP address of its users to let them access the Web anonymously.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Hotspot Shield, AnchorFree, VPN, Apps
Advertisement
Popular Mobile Brands
  1. YouTube Takes on OpenAI's Sora With AI-Generated Shorts Feature
  2. Dhurandhar OTT Release Date Update: When and Where to Watch it Online?
  3. Ubisoft Cancels Prince of Persia: Sands of Time Remake, Delays 7 Games
  4. Realme Neo 8 Launched With 8,000mAh Battery: See Price, Features
  5. Aadukalam Streaming on SunNXT: Know Everything About Plot, Cast, and More
  6. Top Last Minute Deals on Smartphones, Smart TVs and Home Appliances
  7. Here's When the Redmi Note 15 Pro and Note 15 Pro+ Will Launch in India
  8. OnePlus 15T Spotted on Certification Site, Charging Details Revealed
  9. OnePlus Nord 6 Arrives on Geekbench With These Key Specifications
  10. Crimson Desert Has Officially Gone Gold, Pearl Abyss Confirms
  1. Realme Neo 8 Launched With Snapdragon 8 Gen 5 Chip, 8,000mAh Battery: Price, Features
  2. Apple Asks Delhi High Court to Stop Competition Commission of India From Seeking Its Financials
  3. Amazon Great Republic Day Sale: Top Last Minute Deals on Smartphones, Smart TVs and Home Appliances
  4. Amazon Great Republic Day Sale: Best Deals on Robot Vacuum Cleaners
  5. OnePlus 15T Lands on 3C Certification Database Ahead of Launch in China: Expected Specifications
  6. Crimson Desert Has Officially Gone Gold, Launch Set for March 19
  7. Acer Chromebook Spin 311, Chromebook 311 Launched With MediaTek Kompanio 540 CPU: Price, Features
  8. Samsung Galaxy S26+ Bags 3C Certification; Might Not Launch With Charging Upgrade
  9. Apple Could Turn Siri Into an AI Chatbot to Rival OpenAI, Google: Report
  10. Powerful X-Class Solar Flare Sends CME Toward Earth, Storms Possible
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.