FINDING · DETECTION

All six Chinese browsers (Baidu Searchbox, UC Browser, QQ Browser, OPPO, Redmi/Mi, VIVO) transmit the full URL of every page visited—including HTTPS pages—along with page titles and search terms out-of-band to vendor servers, entirely bypassing VPN tunnel protection. In five of six cases this data is transmitted with no cryptography or weak cryptography (purely symmetric AES with hardcoded keys, or textbook RSA with a 128-bit modulus factorable in under 3 seconds), making it readable by any on-path actor between the VPN egress and the vendor's servers.

From 2025-rodriguez-revisitingRevisiting BAT Browsers: Protecting At-Risk Populations from Surveillance, Censorship, and Targeted Attacks · §4.1 · 2025 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dpikeyword-filtering
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.