Executive brief
BlueStacks Player, a popular software for running Android applications on Windows and macOS, contains a security flaw in version 5.20. The application fails to properly verify the identity of the servers it connects to, which could allow a nearby attacker on the same network to intercept or modify data. This could lead to the exposure of sensitive user information during a man-in-the-middle attack.
Technical details
A vulnerability classified as Improper Certificate Validation (CWE-295) exists in BlueStacks Player v5.20. The application does not correctly validate SSL/TLS certificates during network communications. An attacker positioned on the same local network (adjacent attack vector) could exploit this by presenting a forged certificate to intercept encrypted traffic. Successful exploitation allows for man-in-the-middle (MITM) attacks, potentially leading to the disclosure or modification of sensitive information. The CVSS assessment indicates high complexity and high privileges are required for successful exploitation.
Affected products
- BlueStacks BlueStacks Player 5.20
Timeline
- 2025-08-05: advisory: Initial disclosure by Claroty Team82 and NVD publication.