{"id":215625,"date":"2023-03-09T03:49:06","date_gmt":"2023-03-09T08:49:06","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=275437"},"modified":"2025-07-01T19:52:37","modified_gmt":"2025-07-02T02:52:37","slug":"if-you-buy-at-shein-with-your-mobile-be-careful-your-app-hid-a-dangerous-bug","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/if-you-buy-at-shein-with-your-mobile-be-careful-your-app-hid-a-dangerous-bug\/","title":{"rendered":"Is Shein&#8217;s app putting your phone at risk? Shocking new discovery revealed"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">One of the greatest conveniences offered by the Internet is the possibility of <strong>buying anything<\/strong> without leaving your living room. For this reason, in recent years options such as <a href=\"https:\/\/aliexpress-sale.en.softonic.com\/\">AliExpress<\/a>, <a href=\"https:\/\/ebay-for-firefox.en.softonic.com\/\">eBay<\/a> or <a href=\"https:\/\/amazon-windows-10.softonic.com\/\">Amazon<\/a> have not stopped growing and gaining followers, a <strong>select group<\/strong> joined by the <strong>Shein<\/strong> platform after conquering more than 100 million users on Android devices. However, an investigation has revealed that the well-known fashion app had a <strong>malicious error<\/strong> that gave access to personal data and, until it was corrected, it was active for <strong>half a year<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Shein APK\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-m\/p\/fd52ce52-d744-4522-9071-19a225064834\/3453916106\/shein-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Shein APK<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/shein.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/shein.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This information comes from <a href=\"https:\/\/thehackernews.com\/2023\/03\/sheins-android-app-caught-transmitting.html\">The Hacker News<\/a>, an Anglo-Saxon portal specialized in system vulnerabilities. In a recent news item, they report that a Shein bug made it possible to periodically capture and send <strong>the contents of the clipboard<\/strong> to a remote server. For those who are not familiar with the clipboard function, this is the tool that manages the content that the user has copied. Thus, those who have chosen to copy a password, personal data or an excerpt of a conversation, put their information at risk without knowing it. But luckily for Shein users and shoppers, this bug was fixed <strong>almost a year ago<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As they point out in the news, this problem was related to <strong>version 7.9.2<\/strong> of the Shein app on Android, a revision that saw the light of day last <strong>December 16, 2021<\/strong>. Since then, all users saw their private information exposed, a situation that came to an end when the bug was fixed in <strong>May 2022<\/strong>. Today, almost a year later, Shein has <strong>version 9.0.0<\/strong>, an update free of such errors. And, as a direct consequence, both those in charge of the application and those responsible for Google introduced various changes to prevent this situation from recurring.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Google Chrome\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-m\/p\/b2e6d43a-96bf-11e6-a674-00163ed833e7\/965337810\/chrome-Google_Chrome_logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Chrome<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/chrome.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/chrome.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As reported by members of Shein itself, one of the star apps for gifting at any time of the year, no member had specific knowledge of <strong>malicious intent<\/strong> behind such behavior. <a href=\"https:\/\/www.en.softonic.com\/s\/google\">Google<\/a>, for its part, introduced a series of measures to prevent apps from accessing the clipboard. These include a warning when an app intends to do so and a ban on apps attempting to obtain data while not running in the foreground. In this way, Google made sure to protect clipboards, a tool they consider key as it allows attackers to collect useful <strong>information and data<\/strong> from their targets.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The popular fashion platform spied on users without their consent<\/p>\n","protected":false},"author":9261,"featured_media":215626,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-215625","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/215625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9261"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=215625"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/215625\/revisions"}],"predecessor-version":[{"id":321824,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/215625\/revisions\/321824"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/215626"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=215625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=215625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=215625"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=215625"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=215625"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=215625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}