A security consultant has notified Skype of a cross-site scripting flaw that could be used to change the password on someone’s account, according to details posted online.
There are some mitigating factors, such as that the attacker and victim must be friends on Skype. Also, the attack may not immediately execute when the victim logs in. Kayan said he noticed the behavior happened only after the victim logged in several times. But he said in an e-mail that once it happens the first time, “it happens with each re-login.”
Skype should be checking the input into the mobile phone field and validating that it is indeed a phone number and not executable code. The problem affects the latest version of Skype, 188.8.131.52, on Windows XP, Vista and 7 as well as Mac OS X operating system.