Habr•August 3, 2026•🇷🇺Translated from Russian

Yandex Apps Leak Pre-Trigger Audio Buffers, Payment Data, and Contacts via Reverse Engineering

Security researchers have reverse-engineered two Yandex Android applications and uncovered extensive surveillance capabilities that affect millions of users across Samsung, Xiaomi, Honor, and Realme devices. The findings, presented in a multi-part series, detail how Yandex Search and Yandex Browser collect audio, location, payment, and contact data with minimal user visibility.

Audio Pre-Trigger Buffer

The voice assistant Alice continuously records microphone input into a ring buffer. When the wake word is detected, the application sends the preceding audio segment to Yandex servers. The buffer size is not fixed in code but is controlled remotely through parameters such as HasPreroll, buffer-size-ms, and loggingSoundLengthBeforeTriggerMs. Default configuration uses 48000 samples at 16 kHz, equaling three seconds, yet the server can extend this window arbitrarily or disable the feature entirely.

Audio flows from AudioRecord through the circular buffer, Opus or AAC encoding, and WebSocket transmission to wss://uniproxy.alice.yandex.net. The pre-trigger content is also used for biometric voiceprint construction.

WiFi Fingerprinting and Passive Geolocation

Applications scan nearby WiFi access points, collecting BSSID, SSID, and RSSI values. These data are sent to startup.mobile.yandex.net for server-side geolocation accurate to 10-50 meters indoors. The same mechanism registers a passive location provider that intercepts coordinates obtained by any other application on the device and records cellular tower identifiers including MCC, MNC, Cell ID, and LAC/TAC.

Payment Data Handling

Before tokenization, primary account number (PAN) and CVV values are transmitted to mobpayment.yandex.net. Researchers contrast this server-side approach with client-side tokenization used by Stripe, Braintree, and Adyen, noting that any logging failure or compromise of intermediate servers could expose card details.

JavaScript Bridge and Contact Exfiltration

Twenty-one addJavascriptInterface calls expose 94 @JavascriptInterface methods. Any cross-site scripting vulnerability on a yandex.ru subdomain grants attackers direct access to native device functions. Contact data are monitored in real time via ContentObserver on ContactsContract.Contacts.CONTENT_URI. Names, phone numbers, emails, organizations, photos, and call logs are serialized with protobuf and uploaded over HTTP POST with OAuth authorization. The application also reads numbers from WhatsApp, Telegram, and Viber using MIME-type filters.

Additional Surveillance Mechanisms

Runtime.getRuntime().exec("logcat -d") attempts to capture system logs, which are AES-encrypted and exfiltrated. PackageManager.getInstalledApplications and shell commands enumerate all installed applications, including banking apps, VPN clients, and content blockers. Hardcoded DNS servers 77.88.8.8 and 77.88.8.1 bypass system, VPN, and DoH configurations. A native library, libquarkenstein_daemons.so, implements audio pipelines, process manipulation, and encryption routines.

Remote configuration flags exceeding seventy allow the server to enable map saving, force Alice activation, or delay permission requests for years. The analysis concludes that these practices operate within the bounds of the published terms of service yet rely on architecture considered outdated by modern payment and privacy standards.

Related articles

Habr•Privacy & Surveillance

Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection

A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.

AntiMalware•Privacy & Surveillance

WhatsApp Introduces Parental Controls for Teen Privacy Settings

WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.

Securitylab•Privacy & Surveillance

Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained

A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.

Habr•Privacy & Surveillance

Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing

Yandex has detailed a cryptographic scheme using Oblivious Pseudorandom Function (OPRF) to help Russian audiovisual services comply with new legislation requiring transmission of user identifiers linked to phone numbers. The approach replaces a naive shared-secret hashing method that created a single point of compromise across dozens of competing companies. Instead, two independent third parties each hold separate secret keys and process blinded elliptic-curve points derived from normalized E.164 phone numbers. Services obtain deterministic identifiers without learning the third-party keys and without exposing raw numbers to the authorized research organization. The design distributes trust, limits offline brute-force attacks to scenarios requiring both keys plus final identifiers, and adds rate limits plus key-rotation capabilities to deter abuse. Yandex positions the solution as a practical compromise between regulatory demands, competitive secrecy, and user privacy.