Recently, Xiong et al. proposed an efficient certificateless aggregate signature (CLAS) scheme for mobile computation. They demonstrated that their scheme is provably secure in the random oracle model. Unfortunately, by giving a concrete attack, in this paper, we point out that Xiong et al.’s scheme is not secure at all and an adversary without the partial private key and the secret value could forge a legal message. Hence, Xiong et al.’s scheme is not feasible for practical applications.

