‘Billions of Android Devices Vulnerable to ‘Dirty Stream’ Cyber Attack’

Published:

spot_img

Critical Security Vulnerabilities Discovered in Popular Android Apps by Microsoft Researchers

Billions of Android Installations at Risk of Compromise Due to Security Weakness

Researchers from Microsoft have uncovered a major security flaw in several Android applications, putting billions of installations at risk of compromise. The vulnerability allows for remote-code execution attacks, token theft, and other issues due to a common security weakness.

The affected apps include popular ones with over 500 million installations each, such as Xiaomi Inc.’s File Manager and WPS Office. Microsoft alerted Google’s Android security research team about the problem, leading Google to release new guidance for Android app developers on how to recognize and address the issue.

According to Microsoft, the flaw stems from Android apps sharing files with other applications using a feature called “content provider.” This feature acts as an interface for managing and exposing an app’s data to other installed applications, but it lacks proper content validation procedures. This oversight allows attackers to send files with malicious filenames to receiving apps, potentially leading to unauthorized access and compromise.

Microsoft has urged app vendors to review their products for similar vulnerabilities and take necessary steps to fix them. Both Microsoft and Google have provided recommendations for developers to prevent such security risks. In the meantime, users can protect themselves by updating their apps regularly and downloading only from trusted sources.

spot_img

Related articles

Recent articles

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...