Blog | G5 Cyber Security

Skype update enables account theft

Recent update to Skype 5.5 for Windows contains a severe security vulnerability that allows attackers to get control of your Skype account. The client executes JavaScript code in Facebook status messages without filtering. In this way, an attackers can capture a Skype user’s cookie, and hence that user’s Skype session. The perpetrator does not even need to be Facebook friends with the victim for the attack to succeed because JavaScript code is also executed on fan sites, where everyone generally has write access. Skype has confirmed it is working on a fix for the problem.”]

Source: http://www.h-online.com/security/news/item/Skype-update-enables-account-theft-Update-1288403.html

Exit mobile version