Critical Vulnerability in YONO SBI App Exposes Users to Man-in-the-Middle Attacks

A serious security flaw has been identified in the YONO SBI: Banking & Lifestyle app, potentially putting millions of users at risk of man-in-the-middle (MITM) attacks. This vulnerability, labeled CVE-2025-45080, affects version 1.23.36 of the app, developed by the State Bank of India (SBI).


Nature of the Vulnerability
Security researcher Ishwar Kumar discovered that the app allows cleartext network traffic due to the android:usesCleartextTraffic=”true” setting in its manifest file. This configuration permits unencrypted data transmission over HTTP instead of the secure HTTPS protocol, creating a significant security gap.
Potential Risks
The implications of this vulnerability are severe:
- Eavesdropping: Attackers can intercept unencrypted data, including user credentials and transaction details.
- Tampering: Malicious actors can modify data packets, altering transaction details or injecting harmful content.
- MITM Attacks: Users may unknowingly connect to rogue servers, allowing attackers to impersonate the bank and steal sensitive information.


The vulnerability has been rated as critical due to its ease of exploitation and potential impact on user confidentiality and data integrity.
As of July 2, 2025, SBI has not issued any public statement regarding a patch or mitigation steps.
Recommendations for Users
Until a fix is available, users are advised to:
- Avoid using public Wi-Fi when accessing the YONO SBI app.
- Monitor accounts for unusual activity.
- Update the app immediately once a security patch is released.
- Other (43)
- Ransomware (154)
- Events and News (27)
- Features (45)
- Security (485)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (36)
- Activation (7)
- Dealers (1)
- Bank Phishing (52)
- Malware Alerts (231)
- Cyber Attack (302)
- Data Backup (13)
- Data Breach (129)
- Phishing (165)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (71)
- Android Security (77)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (75)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (25)
- Uber (1)
- YouTube (1)
- Trojan (4)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (41)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (30)