loader image
Roundcube flaw lets hackers find tiny blue dot on email screen, magnified by hand, linked by data path to servers
Roundcube Flaw Lets Hackers Track Email Opens

A critical Roundcube flaw lets hackers bypass user privacy settings and track when emails are opened, even after users disable remote image loading. The issue, uncovered by security researchers at NULL CATHEDRAL, affects Roundcube Webmail versions before 1.5.13 and all 1.6.x releases prior to 1.6.13.

Attackers exploited a loophole in the HTML sanitizer “rcube_washtml,” which failed to treat the SVG element “feImage” as an image source. Malicious actors used this oversight to embed invisible tracking pixels within email messages. When users opened the email, the embedded SVG filter triggered a GET request to a remote server.

The flaw enabled intruders to confirm active email addresses, collect IP addresses and fingerprint devices. Roundcube resolved the issue in commit 26d7677 by updating its filtering logic to block image loads through SVG filters.

Administrators should patch immediately with the 1.5.13 or 1.6.13 release, as the Roundcube flaw lets hackers compromise user privacy.

Roundcube Webmail Vulnerability Let Attackers Track Email Opens

Write a Reply or Comment

Your email address will not be published. Required fields are marked *