chiprook
← Security
SecuritySeptember 29, 2026, 18:59

Proton Mail left sender-spoofing flaw unfixed for 16 months

A researcher found that Proton Mail allowed sender spoofing via display-name homographs, using Cyrillic characters that mimic Latin letters. Proton acknowledged the flaw and paid the researcher but left it unfixed for 16 months without notifying users.

Proton Mail left sender-spoofing flaw unfixed for 16 months
#ProtonMail
Read next
Gaming

Guild Wars 3 dev wants you to be able to take a break for months at a time and know you're 'not going to be left behind'

Security

OnePlus leaves OxygenOS root flaws unpatched for six months

Security

Fake SARS e-mails get smarter this tax season

Security

69th IT Press Tour: HYCU says the next thing to wipe your data will be fully authorised, and backup is the only undo left