CVE-2025-45080: YONO SBI app vulnerability, explained

A critical flaw in the YONO SBI app allows attackers to intercept banking data via MITM attacks due to insecure HTTP settings. Learn how CVE-2025-45080 impacts users and how to protect your data.

Jul 03, 2025 - 09:42
Updated: 8 days ago
111.1k
CVE-2025-45080: YONO SBI app vulnerability, explained

Quick answer: CVE-2025-45080 is a published vulnerability record stating that version 1.23.36 of the YONO SBI app used unencrypted communication in places, which could let an attacker on the same network intercept data through a man-in-the-middle attack. It describes a weakness, not a confirmed breach. Update the app, check the current status with SBI and avoid untrusted Wi-Fi for banking.

Key takeaways

  • CVE-2025-45080 reports unencrypted communication in YONO SBI version 1.23.36, which could enable a man-in-the-middle attack.
  • A CVE describes a vulnerability, not proof that customer data was actually stolen.
  • A man-in-the-middle attack needs the attacker to be positioned on the network path, for example on an unsafe public Wi-Fi.
  • Users should keep the app updated and avoid untrusted networks for banking.
  • Confirm the current patch status directly with SBI before assuming it is fixed or unfixed.

What is CVE-2025-45080?

CVE-2025-45080 is a published vulnerability record. It states that version 1.23.36 of the YONO SBI: Banking & Lifestyle app was found to use unencrypted communication in places, which could let an attacker carry out a man-in-the-middle attack. The CVE entry and security researcher writeups, including coverage at Cybersecurity News, describe the finding. This article summarises published reporting. Confirm the current status directly with SBI or its official YONO channels, since app versions and fixes change.

What does "unencrypted communication" mean here?

Normally, a banking app should send all data over encrypted HTTPS, so that anyone intercepting the traffic sees only scrambled data. If part of an app's communication is not encrypted, data travelling over that connection can potentially be read or altered by someone positioned between the app and the server.

What is a man-in-the-middle attack?

An attacker places themselves on the network path between the victim and the legitimate server, often by controlling or spoofing a Wi-Fi hotspot, and reads or modifies traffic that is not properly encrypted or verified.

Does this mean SBI customers were hacked?

A CVE record describes a weakness that researchers found, usually through responsible disclosure. It does not, by itself, prove that any customer's data was actually intercepted. Treat the finding seriously but do not assume a breach happened without an official statement confirming one.

What should you do as a user?

  1. Update the app to the latest version from the official app store.
  2. Avoid banking on public or unknown Wi-Fi. Use mobile data or a trusted network instead.
  3. Check for HTTPS indicators where the app shows them, and keep your phone's operating system updated.
  4. Watch your account for unfamiliar transactions and enable alerts.
  5. Contact SBI's official support if you have concerns, and avoid unofficial links claiming to be YONO updates.

What should developers learn from this class of bug?

  • Enforce TLS for every network call, with no fallback to plain HTTP.
  • Use certificate pinning where appropriate for high-value apps.
  • Run regular penetration testing, including on mobile apps, not only web applications.
  • Set up a clear vulnerability disclosure channel so researchers can report issues responsibly.

How are vulnerabilities like this tracked?

Through public databases such as the National Vulnerability Database, which lists CVE entries with severity scores. Reading a CVE entry and its references is a basic skill for anyone in security, and it beats repeating a headline. Our VAPT course builds this skill, and CERT-In tracks vulnerabilities affecting Indian users.

Where does this fit in Indian cybersecurity practice?

Report suspected banking fraud to your bank immediately and to the National Cyber Crime Reporting Portal at cybercrime.gov.in, or call 1930. CERT-In also tracks vulnerabilities affecting Indian users.

Next steps

To learn how such vulnerabilities are found and reported responsibly, see our VAPT course. For a similar case involving fake banking apps, read the fake SBI Rewardz app alert.

Related reading

Frequently Asked Questions

It is a published vulnerability record stating that version 1.23.36 of the YONO SBI app used unencrypted communication in places, which researchers said could allow a man-in-the-middle attack.

Not necessarily. A CVE record describes a confirmed weakness, not proof that any specific customer's data was intercepted. Confirm the current status with SBI's official channels rather than assuming a breach occurred.

It is when an attacker positions themselves on the network path between a user and a server, often through unsafe Wi-Fi, and intercepts or alters traffic that is not properly encrypted.

Keep the app and your phone updated, avoid public or unknown Wi-Fi for banking, use mobile data when possible, watch your account for unfamiliar activity and contact your bank's official support with concerns.

They enforce HTTPS for every network call with no fallback to plain HTTP, use certificate pinning where appropriate, test regularly including on mobile apps, and provide a clear channel for responsible vulnerability disclosure.

Look it up on the National Vulnerability Database or the CVE Program's own site for the official description, severity score and references, and check the vendor's own security advisories for fixes.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.