WPS for Windows may have a remote code execution vulnerability in some versions, as multiple users have reported private key theft.
According to community sources, several members of the cryptocurrency community have reported their private keys being stolen on August 26th. Some speculate that this is due to the use of the Bitpie browser.
In response, the official Bitpie browser community stated that there is a remote code execution vulnerability in some versions of WPS for Windows, which attackers can exploit to execute arbitrary code on the victim's target host and control the host.
The affected versions include WPS Office 2023 personal version below 12.1.0.15120 (inclusive) and WPS Office institutional versions (such as professional and professional enhanced versions) below 11.8.2.12055 (inclusive). The vulnerability is relatively easy to trigger, and users may have already been attacked by hackers after clicking on unknown links.