Proton Mail left sender-spoofing flaw unfixed for 16 months
A researcher found that Proton Mail allowed sender spoofing via display-name homographs, using Cyrillic characters that mimic Latin letters. Proton acknowledged the flaw and paid the researcher but left it unfixed for 16 months without notifying users.
- Attack exploits homographs in the display name, e.g. Cyrillic "о" (U+043E) for Latin "o" (U+006F)
- Display-name field is decoupled from the verified domain, enabling impersonation of banks and PayPal
- Proton Mail acknowledged the flaw and paid the researcher but deprioritized the fix
- Users were not informed, raising phishing and data-theft risks
Read next
Gaming