• Latest
  • Trending
Major Android security leak affects millions of devices – Android Headlines

Major Android security leak affects millions of devices – Android Headlines

02.12.2022
Microsoft’s new AI-powered Bing brings a chatbot to the search field – The Washington Post

Microsoft’s new AI-powered Bing brings a chatbot to the search field – The Washington Post

08.02.2023
Stocks make the biggest moves after hours: Chipotle, Enphase Energy, Fortinet and more – CNBC

Stocks make the biggest moves after hours: Chipotle, Enphase Energy, Fortinet and more – CNBC

08.02.2023
Shoppers browse bottles of this $14 face oil that leaves eye wrinkles ‘almost completely gone’ – Yahoo Life

Shoppers browse bottles of this $14 face oil that leaves eye wrinkles ‘almost completely gone’ – Yahoo Life

08.02.2023
The 256GB Samsung Galaxy S22 has never been cheaper – Android Police

The 256GB Samsung Galaxy S22 has never been cheaper – Android Police

08.02.2023
Porsche 911 GT3 Drag Races Itself in Manual Duel Against PDK

This 1997 Plymouth Neon Has 11,000 Miles, Autographs From Super Bowl Champions

08.02.2023
Basketball Scoreboard: Pair of double-doubles send Christian Lanier girls past America’s Young Christians – Yahoo News

Maine Basketball Hall of Fame Announces Class of 2023 – Yahoo News

08.02.2023
Animal shelter names puppies after Taylor Swift songs after… – 97.9 WRMF

Animal shelter names puppies after Taylor Swift songs after… – 97.9 WRMF

08.02.2023
State of the Union 2023: Who is the designated survivor?  – BBC

State of the Union 2023: Who is the designated survivor? – BBC

08.02.2023
European stocks weaken for the first time in two days – MarketWatch

France Issues €5 Billion in Government Bonds in May 2054 – Update – MarketWatch

08.02.2023
Samsung Galaxy S23 Ultra vs Huawei Mate 50 Pro: Camera – HC Newsroom

Samsung Galaxy S23 Ultra vs Huawei Mate 50 Pro: Camera – HC Newsroom

08.02.2023
Jonathan Majors opens up about his anger at his dad for abandoning him and more

Jonathan Majors opens up about his anger at his dad for abandoning him and more

08.02.2023
WISeArt Announces Valentine’s Day Extravaganza: Famous Famous Designer Bjorn Vandenberg Launches Phygital Jewelry With WISeKey On His Dedicated NFT Platform, WISE.ART – Yahoo Finance

WISeArt Announces Valentine’s Day Extravaganza: Famous Famous Designer Bjorn Vandenberg Launches Phygital Jewelry With WISeKey On His Dedicated NFT Platform, WISE.ART – Yahoo Finance

08.02.2023
Wednesday, February 8, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Major Android security leak affects millions of devices – Android Headlines

Major Android security leak affects millions of devices – Android Headlines

02/12/2022 12:30:13
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

The 256GB Samsung Galaxy S22 has never been cheaper – Android Police

The 256GB Samsung Galaxy S22 has never been cheaper – Android Police

08.02.2023
Samsung Galaxy S23 Ultra vs Huawei Mate 50 Pro: Camera – HC Newsroom

Samsung Galaxy S23 Ultra vs Huawei Mate 50 Pro: Camera – HC Newsroom

08.02.2023

A recent post on Google’s Android Partner Vulnerability Initiative (APVI) website revealed a major Android security leak. The leak has left devices from Samsung, LG, Xiaomi and many other brands vulnerable to very, very dangerous malicious apps. These applications can obtain the same level of access to the affected devices as the operating system itself.

Millions of Android devices are vulnerable to dangerous malicious apps

The problem stems from leaked platform certificates. These certificates or signing keys determine the legitimacy of the version of Android on a device. Vendors also use these certificates to sign applications. While the Android operating system assigns a unique user identifier (UID) to each app upon installation, apps that share signing keys can also have a shared UID and have access to each other’s data. And thanks to this design, applications signed with the same certificate as the operating system itself also get the same privilege.

The problem here is that several companies have had their Android platform certificates leaked to the wrong people. Certificates are now being misused to sign malicious apps with the same privileges as the Android operating system. Apps can obtain system-level permissions on affected devices without user intervention. Thus, as soon as the malware-laden application is installed on a device, its creators can obtain all the data they want from the device without the victim noticing (via).

Companies that sign apps with platform certificates make this leak even more dangerous. Bad actors don’t even need to create new apps and trick potential victims into installing them. Instead, they can simply grab an app signed with the leaked keys, such as Samsung’s Bixby Routines and Galaxy Watch plugins, add malware to it, sign it with the same key, and push it as an update. Of course, they can distribute the app through the Play Store, but Android would consider it a legitimate update even if users sideload the malicious app.

Google hit manufacturers who took corrective action

According to Google, this Android security leak was first reported in May this year. All affected manufacturers have already “taken corrective action to minimize the impact of the leak on the user”. But users may still be vulnerable if they have already installed the malicious app on their device. Worse still, some of the malware examples may have been active since 2016. If you are using an older Android device, we advise you to upgrade to a newer model that is actively receiving security updates. You should also avoid downloading apps and always install apps from the Google Play Store.

Meanwhile, Google recommends Android vendors to replace compromised platform certificates and do so regularly to avoid similar issues in the future. Organizations should also avoid using platform certificates to sign applications to minimize risk. Let’s hope Android OEMs act on these recommendations and put user privacy and security above everything else.

Related

Previous Post

Moore signs with Ronaldo and Beyoncé’s talent agency – Westmeath Independent

Next Post

Gary Neville claims Unai Simon is Spain’s ‘weakest link’ after goalkeeper blunder against Japan, insists David de Gea saved Ritsu Doan’s equalizer

Related Posts

The 256GB Samsung Galaxy S22 has never been cheaper – Android Police
Technology

The 256GB Samsung Galaxy S22 has never been cheaper – Android Police

08.02.2023
0

Pay less for more storage space Galaxy S22 The Samsung Galaxy S22 is now on sale on Amazon, with the...

Read more
Samsung Galaxy S23 Ultra vs Huawei Mate 50 Pro: Camera – HC Newsroom

Samsung Galaxy S23 Ultra vs Huawei Mate 50 Pro: Camera – HC Newsroom

08.02.2023
TSMC-Sony JV revitalizes “Silicon Island” in Japan

TSMC-Sony JV revitalizes “Silicon Island” in Japan

08.02.2023

How to Use Terminal on Your Mac – The Mac Observer

08.02.2023

Android 13 begins rolling out to Google TV developers – The Desk

08.02.2023

Samsung just dropped some major Galaxy deals to mark the launch of the new Galaxy S3 phone

07.02.2023
Load More
Next Post
Gary Neville claims Unai Simon is Spain’s ‘weakest link’ after goalkeeper blunder against Japan, insists David de Gea saved Ritsu Doan’s equalizer

Gary Neville claims Unai Simon is Spain's 'weakest link' after goalkeeper blunder against Japan, insists David de Gea saved Ritsu Doan's equalizer

Recent Posts

  • Microsoft’s new AI-powered Bing brings a chatbot to the search field – The Washington Post
  • Stocks make the biggest moves after hours: Chipotle, Enphase Energy, Fortinet and more – CNBC
  • Shoppers browse bottles of this $14 face oil that leaves eye wrinkles ‘almost completely gone’ – Yahoo Life
  • The 256GB Samsung Galaxy S22 has never been cheaper – Android Police
  • This 1997 Plymouth Neon Has 11,000 Miles, Autographs From Super Bowl Champions

Archives

  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • 0
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.