Microsoft discovered a path traversal-affiliated vulnerability pattern in multiple popular Android applications that could enable a malicious application to overwrite files in the vulnerable application’s home directory.
The implications of this vulnerability pattern include arbitrary code execution and token theft, depending on an application’s implementation. Arbitrary code execution can provide a threat actor with full control over an application’s behavior. Meanwhile, token theft can provide a threat actor with access to the user’s accounts and sensitive data.
Read more…
Source: Microsoft
Related:
- Android malware BrazKing returns as a stealthier banking trojan
November 18, 2021
The BrazKing Android banking trojan has returned with dynamic banking overlays and a new implementation trick that enables it to operate without requesting risky permissions. A new malware sample was analyzed by IBM Trusteer researchers who found it outside the Play Store, on sites where people end up after receiving smishing (SMS) messages. These HTTPS sites warn ...
- Cyprus: Surveillance firm pays $1 million fine after ‘spy van’ scandal
November 13, 2021
The Office of the Commissioner for Personal Data Protection in Cyprus has collected a $1 million fine from intelligence company WiSpear for gathering mobile data from various individuals arriving at the airport in Larnaca. While this is just an administrative fine under the European Union’s General Data Protection Regulation (GDPR), it is related to a scandal ...
- New PhoneSpy Android Spyware Poses Pegasus-Like Threat
November 10, 2021
Researchers discovered new Android spyware that provides similar capabilities to NSO Group’s Pegasus controversial software. Called PhoneSpy, the mobile surveillance-ware has been spotted activity targeting South Koreans without their knowledge. PhoneSpy disguises itself as a legitimate application and gives attackers complete access to data stored on a mobile device and grants full control over the targeted ...
- Millions of Android Users Scammed in SMS Fraud Driven by Tik-Tok Ads
October 26, 2021
Threat actors are using malicious Android apps to scam users into signing up for a bogus premium SMS subscription service, which results in big charges accruing on their phone bills. Jakub Vavra from the threat operations team of security firm Avast uncovered the campaign, which he dubbed UltimaSMS because one of the first apps he discovered ...
- Google launches Android Enterprise bug bounty program
October 21, 2021
Google has announced the launch of its first vulnerability rewards program for Android Enterprise with bounties of up to $250,000. This builds on the introduction of several enhancements with Android 12 to boost the platform’s overall security. Security enhancements included with the latest Android version range from toggling off USB signaling on enterprise devices to block USB-based ...
- TangleBot Malware Reaches Deep into Android Device Functions
September 24, 2021
An Android malware called TangleBot has weaved its way onto the cyber-scene: One that researchers said can perform a bouquet of malicious actions, including stealing personal info and controlling apps and device functions. According to Cloudmark researchers, the newly discovered mobile malware is spreading via SMS messaging in the U.S. and Canada, using lures about COVID-19 ...

