Latest in Android

Image credit:

First real world 'master key' exploit discovered sneaking malware into Android apps

59 Shares
Share
Tweet
Share

Sponsored Links

Two apps have been discovered on unofficial marketplaces in China that might just be the first in-the-wild exploits of the massive bug found by Bluebox two weeks ago. The so-called "master key" vulnerability, or a least an extremely close relative of it, was the point of entry for malware in these two apps, which now carry code that allows an attacker to remotely hijack a device, harvest sensitive data and even disable a number of mobile security suites. The concern here, is that this particular security hole allowed these alterations to be made without invalidating the apps' digital signatures. So, the malware was able to sneak through filters, hidden as a Trojan Horse inside pieces of legitimate software. Google has already patched the vulnerability, preventing compromised apps from slipping in to the official Play store. Additional updates addressing the flaw have been issued to carriers and manufacturers, but we all know it could be quite sometime before everyone applies the patches to their products.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
59 Shares
Share
Tweet
Share

Popular on Engadget

Get $24 off the Nintendo Switch on Amazon

Get $24 off the Nintendo Switch on Amazon

View
Supreme’s burner phone is a hypebeast’s dream

Supreme’s burner phone is a hypebeast’s dream

View
Nintendo Switch sales top 15 million in North America alone

Nintendo Switch sales top 15 million in North America alone

View
Endel's Apple Watch app generates soothing sounds on your wrist

Endel's Apple Watch app generates soothing sounds on your wrist

View
You can report traffic snarls in Google Maps for iOS

You can report traffic snarls in Google Maps for iOS

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr