This CVE in Agora.io’s SDK Left Video Calling Apps Open to Snooping

Date:

Share post:

McAfee Advanced Threat Research (ATR) team uncovered a critical security vulnerability in Agora, a video calling software development kit (SDK), which could allow an attacker to spy on ongoing video and audio calls. Agora is a video, audio, and live interactive streaming platform used by many social media applications like eHarmony, MeetMe, Plenty of Fish, and Skout, along with health care apps like Talkspace, Practo, and Dr. First’s Backline.

Agora allows app developers to embed voice and video chat, live streaming, real-time recording, and messaging into their applications. It is estimated that Agora’s SDKs are deployed on more than 1.7 billion devices globally.

Vulnerability Patched

The flaw, CVE-2020-25605, transmits cleartext of users’ sensitive information in Agora’s SDK (before 3.1 version) allowing a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic. Upon successful exploitation, the vulnerability could allow threat actors to launch Man-in-the-Middle Attacks (MITM), which occur when a perpetrator stealthily alters the communications between two unwitting users or a user and an application.

While there is no information on whether the vulnerability is being exploited in the wild, McAfee alerted Agora about the vulnerability. As a response, the company released a new SDK (version 3.2.1), which mitigated the vulnerability and eliminated the potential risks to users.

“Agora’s SDK implementation did not allow applications to securely configure the setup of video/audio encryption, thereby leaving a potential for hackers to snoop on them. In the world of online dating, a breach of security or the ability to spy on calls could lead to blackmail or harassment by an attacker. Other Agora developer applications with smaller customer bases, such as the temi robot, are used in numerous industries such as hospitals, where the ability to spy on conversations could lead to the leak of sensitive medical information,” McAfee said.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...