Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Computing
  5. Mobile
  6. Legacy Archives

Beware of ‘Cupid,’ the new Heartbleed attack method that affects Android devices

Add as a preferred source on Google

If you think the Heartbleed Bug threat is over, think again. Less than two months since the security flaw was first exposed, exploiting it just got a lot easier.

According to Portuguese security researcher Luis Grangeia, the new attack method, which has been named Cupid, exploits a vulnerability in OpenSSL the same way as Heartbleed. The only difference is, it would perform its function over Wi-Fi instead of the Internet and targets Android devices.

Recommended Videos

(For more info, read our list of Android devices openly vulnerable to Heartbleed.)

“This is basically the same attack as Heartbleed, based on a malicious heartbeat packet. Like the original attack, which happens on regular TLS connections over TCP, both clients and servers can be exploited and memory can be read off processes on both ends of the connections,” Grangeia said in a blog post.

“The difference in this scenario is that the TLS [Transport Layer Security] connection is being made over EAP [Extensible Authentication Protocol], which is an authentication framework/ mechanism used in Wireless networks. It’s also used in other situations, including wired networks that use 802.1x Network Authentication and peer to peer connections … To exploit vulnerable clients, hostapd (with the cupid path) can be used to setup an “evil” network such that, when the vulnerable client tries to connect and requests a TLS connection, hosted will send malicious heartbeat requests, triggering the vulnerability.”

There are two programs affected by Cupid:

  • Hostapd is used for setting up a configurable access point on Linux.
  • Grangeia said that it is possible to create almost any kind of wireless network configuration and let clients connect to it. The other program, wpa_supplicant, is used for connecting to wireless networks on Linux and Android.

There are two attack scenarios for Cupid. The first one involves an “evil client” that uses an altered wpa_supplicant application for authenticating Wi-Fi communications. An attacker can request a connection to vulnerable server. Once a connection is made, hackers can send heartbeat requests. The second attack scenario involves using an altered hostapd application to access a vulnerable client. This allows attackers to set up a network for sending malicious heartbeat requests.

 According to Grangeia, devices running on Android 4.1.0 and and 4.1.1 are vulnerable. However, the risk is not limited to older software. Grangeia said that since all versions of Android use wpa_supplicant to connect to wireless networks, it is possible that all devices running on the OS may be vulnerable.

Aside from mobile devices, Linux systems and corporate wireless connections are also vulnerable. Home routers, on the other hand, are deemed safe because they do not use EAP.

Grangeia’s findings have inspired dissent from other developers, primarily from FreeRadius, which claims to be the “world’s most popular Radius server.” In response to comments that the Cupid vulnerability has been known early on, he said: “The attack method, however, is new. Up until now there were no publicly available tools that would trigger the Heartbleed vulnerability via EAP.”

Pierluigi Paganini, who works for the European Union Agency for Network and Information Security, explained that an attacker would not need a valid password to exploit the flaw. A username is enough to exploit the vulnerability. A full TLS connection (which allows clients and servers to communicate across a network securely) is also not required since heartbeat requests can be sent and received before keys and certificates are exchanged.

If you have a vulnerable device, we advise that you take steps to protect your information. Grangeia has created patches for vulnerable hostapd and wpa_supplicant applications, which can be found on his Github page.

Christian Brazil Bautista
Christian Brazil Bautista is an experienced journalist who has been writing about technology and music for the past decade…
Galaxy S25 users are finally getting some missing One UI 8.5 AI features
Prioritize Notifications, Summarize Notifications and File Summaries arrive on Galaxy S25, but Now Nudge is still missing
samsung-galaxy-s25

Last month, Samsung rolled out the One UI 8.5 update to the Galaxy S25 series, but users quickly noticed that several AI features available on the Galaxy S26 series were missing. The omissions sparked confusion and frustration, with many Galaxy S25 owners questioning what Samsung’s long-term software support actually covers.

Now, Samsung seems to be fixing part of the issue with the June 2026 update, which reportedly adds three of the missing Galaxy AI features to the Galaxy S25 series. The update has started rolling out in South Korea and includes the June 2026 Android security patch. The firmware has the build number S938NKSUACZF1.

Read more
One UI 9 will finally give Samsung phones a feature most Androids have had for years
The long-missing network speed indicator is finally showing up in One UI 9
Samsung Galaxy S26 Ultra smartphone in blue color.

Samsung is already a few weeks into testing One UI 9 with Galaxy S26 beta users, and a new feature spotted in the latest build feels long overdue. It is the network speed indicator, a simple status bar tool so common on other Android phones that it is surprising Galaxy phones have gone this long without it.

You can find this feature even on budget Android phones from brands like OnePlus, Oppo, and Xiaomi. It shows real-time upload and download activity in the status bar while the phone is connected to Wi-Fi or mobile data, giving users a quick way to check whether their connection is actually moving data.

Read more
Waiting for smartphone prices to drop? Nothing’s CEO has bad news for you
Carl Pei has skin in this game, but the RAM shortage he is describing is real, and the price increases he is pointing to are already showing up in phones you can buy today.
Nothing Phone 4a Pro featured.

If you have been holding off on a new phone hoping for a better deal, perhaps a discount on a model launched in the first quarter of the year, Nothing’s co-founder Carl Pei has a blunt message for you: stop waiting. 

In a post on X, Pei explained how 2026 is reshaping smartphone pricing like never before. The culprit, to no one's surprise, is a component that now makes up more than 50% of the total hardware bill.

Read more