Lo, yonder Bluebox Security’s Bluebox Labs hath unearthed an Android Bug that hath lingered since the Android version 1.6 Donut hath been unleashed upon the world in the year of our Lord 2009. Android, an open source project, doth grant the power to craft apps and vend them in the Play store or any third-party App emporium. Whilst Google doth endeavor to ensure the safety of apps by imbuing them with digital signatures, venturing to download apps from third-party establishments may easily imperil the sanctity of thy device.
Let us now delve into the dark realm of how this transgression doth occur and the dire consequences it may unleash upon thy device.
Android vulnerability:
The Android applications doth make use of cryptographic signatures that the system doth record upon installation of the app. Subsequent updates of said app must bear the same cryptographic signatures. Alas, malefactors may exploit these legitimate cryptographic signatures to tamper with the app, injecting foul code, and then disseminate it through unreliable third-party app bazaars. When the user doth install this nefarious version of the app, it doth masquerade as a Trojan horse, assuming a guise of innocence, yet within lurks malicious intent. By the grace of the Android system’s permissions, this app may seize control of many vital aspects of the system.
What can be hacked or compromised:
The sages at Bluebox Security doth report that miscreants may jailbreak the device, gaining access to all manner of system features, crafting a botnet capable of transforming any innocent app into a Trojan. Furthermore, these Trojan or malicious apps may filch passwords, account details, credit and debit card information from the device, seizing command of the phone, SMS, email, or hardware such as the camera, microphone, and even the very operating system itself.
Who are affected by this vulnerability:
Lo, over 900 million Android devices (be they tablets or phones) running on Android version 1.6 or later, including Jelly bean, art vulnerable to this scourge. The lone device blessed with a remedy for this bug is the Samsung Galaxy S4, as decreed by GSMarena.
How is Google dealing with this problem:
Verily, Google hath acknowledged the existence of this flaw, and the developers and device manufacturers therein are cognizant of this blemish. A patch is said to be forthcoming in future software updates to vanquish this blight.
Google hath also assured the populace that no apps currently reside on Google Play which exploit this weakness; staunch precautions and safety measures art utilized in the curation of apps on the Play Store.
Prevention is better than cure, how to be cautious:
Given that every Android device running Android version 1.6 or later (save for the Galaxy S4) is afflicted by this bug, users should eschew downloading apps from dubious third-party app emporiums offering cracked or pirated apps for free. Though an app may seem secure based on its digital signatures, within may lie insidious code.
Exercise utmost prudence whilst engaging in online transactions through third-party apps; never divulge credit card, debit card, or account details to apps not procured from secure and trusted app purveyors.
Lastly, bestow upon thy device a noble antivirus app and disable the option to install apps from unknown markets in the security settings of thy Android system. Invest in premium versions of antivirus apps, for they do offer greater security features than their free counterparts.
Keep vigilant for forthcoming software updates, for soon, the manufacturers of devices shall mend this infirmity.
Image courtesy: thehackernews
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.
























