‘Billions of Android Devices Vulnerable to ‘Dirty Stream’ Cyber Attack’

Published:

spot_img

Critical Security Vulnerabilities Discovered in Popular Android Apps by Microsoft Researchers

Billions of Android Installations at Risk of Compromise Due to Security Weakness

Researchers from Microsoft have uncovered a major security flaw in several Android applications, putting billions of installations at risk of compromise. The vulnerability allows for remote-code execution attacks, token theft, and other issues due to a common security weakness.

The affected apps include popular ones with over 500 million installations each, such as Xiaomi Inc.’s File Manager and WPS Office. Microsoft alerted Google’s Android security research team about the problem, leading Google to release new guidance for Android app developers on how to recognize and address the issue.

According to Microsoft, the flaw stems from Android apps sharing files with other applications using a feature called “content provider.” This feature acts as an interface for managing and exposing an app’s data to other installed applications, but it lacks proper content validation procedures. This oversight allows attackers to send files with malicious filenames to receiving apps, potentially leading to unauthorized access and compromise.

Microsoft has urged app vendors to review their products for similar vulnerabilities and take necessary steps to fix them. Both Microsoft and Google have provided recommendations for developers to prevent such security risks. In the meantime, users can protect themselves by updating their apps regularly and downloading only from trusted sources.

spot_img

Related articles

Recent articles

Aussie Bank Warns: Rate Change Could Trigger Rise in Scams

Be Alert: Bank Warns of Increased Scams Amidst Rate Changes As the recent drop in interest rates sees the financial landscape shift, ANZ Bank is...

Libyan Journalists Under Pressure: Self-Censorship Amid Online Attacks

Addressing Online Harassment: The Struggles of Journalists in Libya The Context of Online Harassment Journalists in Libya are increasingly facing a troubling environment characterized by online...

Fake DocuSign and Gitcode Sites Distributing NetSupport RAT through Multi-Stage PowerShell Attack

New Threat: Multi-Stage PowerShell Attack Targeting Users Overview of the Campaign Recent alerts from threat hunters indicate an ongoing campaign that leverages deceptive websites to lure...

Billions of Stolen Cookies Still Available Online

Purchases made through links in our articles may result in a commission for Future and its partners. Recent studies by NordVPN uncover 94 billion stolen...