 
                 
            
            Indian Internet security sleuths have alerted consumers of the vulnerability to the Web-based service which affects computer systems and mobile phones using the Android system.
The suspicious activity has been noticed by CERT-In in two Android versions - v4.3 known as 'Jelly Bean' and the latest v4.4 called 'Kit Kat'.
"A critical flaw has been reported in Android's (virtual private network) VPN implementation, affecting Android version 4.3 and 4.4 which could allow an attacker to bypass active VPN configuration to redirect secure VPN communications to a third party server or disclose or hijack unencrypted communications," CERT-In said in a latest advisory to users of this network.
CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of the Indian Internet domain.
VPN technology is used to create an encrypted tunnel into a private network over public Internet. Organisations and groups of people use such connections to enable employees or acquaintances to securely connect to enterprise networks from remote locations through multiple devices, from laptops to desktops to mobiles and tablets.
The agency said the current malicious application is capable of diverting the VPN traffic "to a different network address" and successful exploitation of this issue "could allow attackers to capture entire communication originating from affected device."
"It is noted that not all applications are encrypting their network communication. Still there is a possibility that attacker could possibly capture sensitive information from the affected device in plain text like email addresses, IMEI number, SMSes, installed applications," the advisory said.
Cyber-experts said that this anomaly could only lead to capture and viewing the data which is in plain text and Android applications directly connecting to the server using SSL will not be affected.
Websites which use 'https' in their URL will also be safe.
The cyber-agency has also suggested some countermeasures to beat this threat.
"Apply appropriate updates from the original equipment manufacturer, do not download and install applications from untrusted sources, maintain updated mobile security solution or mobile anti-virus solutions on the device, exercise caution while visiting trusted or untrusted URLs and do not click on the URLs received via SMS or email unexpectedly from trusted sources, or received from untrusted users" are some of the combat techniques which have been suggested by the agency.For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.
 HMD Fusion 2 Key Features, Specifications Leaked Online: Snapdragon 6s Gen 4, New Smart Outfits, and More
                            
                            
                                HMD Fusion 2 Key Features, Specifications Leaked Online: Snapdragon 6s Gen 4, New Smart Outfits, and More
                            
                        
                     Google Says Its Willow Chip Hit Major Quantum Computing Milestone, Solves Algorithm 13,000X Faster
                            
                            
                                Google Says Its Willow Chip Hit Major Quantum Computing Milestone, Solves Algorithm 13,000X Faster
                            
                        
                     Garmin Venu X1 With 2-Inch AMOLED Display, Up to Eight Days of Battery Life Launched in India
                            
                            
                                Garmin Venu X1 With 2-Inch AMOLED Display, Up to Eight Days of Battery Life Launched in India
                            
                        
                     iPhone 18 Series, Apple's First Foldable iPhone Tipped to Feature Company's First 2nm A20 Chip
                            
                            
                                iPhone 18 Series, Apple's First Foldable iPhone Tipped to Feature Company's First 2nm A20 Chip