
Alipay Vulnerabilities Allow Silent GPS Data Exfiltration
CybersecurityVulnerabilitiesAlipayGPSExfiltrationCVECVSSAlibabaJSBridgeWebView
A researcher discovered 17 vulnerabilities in Alipay, enabling a crafted URL to silently exfiltrate GPS coordinates (8.8m accuracy within 7 seconds) without user prompts. The attack chain exploited a trusted domain redirect, deep links, and a privileged WebView to call Alipay’s JSBridge API. Six CVEs (CVSS 7.4–9.3) were submitted, with 308 server-side GPS logs collected across three devices and countries, including the vendor’s security lead. Alibaba, a registered CNA, initially refused to assign CVEs, and the vendor later issued a takedown complaint.