Android app vulnerabilty puts Chinese users at-risk

Share this article:

A recently discovered Android vulnerability puts Chinese users' information at-risk through phony app updates.

The vulnerability allows fake apps to hijack real app updates then use them to steal stored information, according to researchers at Trend Micro. It targets mainly Chinese users because they often update their apps directly, as opposed to going through Google Play or another third-party app store.

The phone owner can download an update's Android application package (APK) file to a SD card directly from the app, which leaves information vulnerable because the APK file is unverified and could have been replaced with a malicious file.

But Google Play, for instance, checks whether updates are legitimate and distributes the updates as they come in. The researchers recommend all apps be downloaded and updated from official app sites.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.