• Home Page
  • About Us
  • Advertise
  • Contact Us
  • My Account

TechVisibility

  • Home page
  • News
  • Computing
  • Reviews
  • Apps
  • Gaming
  • Mobile
  • Audio
  • Video
  • Gadgets
  • FinTech
  • EV
  • More
    • Antivirus
    • Cameras
    • Cryptocurrency
    • NFT
    • Phones
    • Security
    • Smart Home
    • Software
    • Streaming
    • TVs
    • Wearables
    • Web hosting
    • What To Watch
You are at :Home»Apps»Popular Android Apps Are Vulnerable Due to Google Play’s Major Flaw
Arget on Unsplash

Popular Android Apps Are Vulnerable Due to Google Play’s Major Flaw

Noah Gravel 04 Dec 2020 Apps, Security Leave a comment 784 Views

Facebook Twitter linkedin Pinterest Tumblr WhatsAppt Telegram Email More

Many popular Android apps are currently vulnerable to dangerous hacks. A major flaw in Google Play Core Library is causing this issue.

Markus Spikes Iar on Unsplash

Most of these applications are receiving hundreds of millions of downloads. This is obviously bad news since most of the apps are used by many people across the world.

These include the PowerDirector video editor, the XRecorder video and screen recorder, the Edge Browser, and many more. The Android apps are commonly used during the pandemic since most works are now home-based.

Security researchers explained that this is a serious security issue right now. Why? Because Google Play Core Library is a collection of Google codes.

This area allows apps to streamline the update process. The Android apps can do it by receiving new versions during runtime and tailoring updates.

These system updates happen in an app’s specific configuration or a specific model the app is running on.

Google Play Core Library’s flaw

The new flaw in Google Play Library came from a directory traversal issue. The previous security flaw allowed hackers to copy files to a folder.

Arget on Unsplash

However, the folder is supposed to be reserved only for trusted code received from Google Play. The new vulnerability breaches core protection built into the Android operating system.

This security layer prevents an app from accessing data or code from any other app. Google announced that it already patched the major flaw in April.

But, developers still need to download the updated library. They also need to incorporate it into their app code to fix the vulnerable apps.

As of the moment, security experts are still seeing numerous developers using the vulnerable library version.

The new flaw allows hackers to access user’s Dropbox account

Check Point, the security firm that discovered the issue, used a proof-of-concept malicious app. This allowed the researchers to steal an authentication cookie from Chrome’s old version.

They found out that the attacker can gain unauthorized access to a victim’s Dropbox account using the cookie. Check Point also identified 14 apps with combined downloads of around 850 million.

It will be a serious problem once they are breached. Why? Because they also have 160 million total installations.

As of the moment, Check Point hasn’t confirmed if these vulnerable apps are already fixed.

Protecting your Android apps

There are lots of ways for you to protect your Android apps. The first thing you need to do is to enforce secure communication.

This means that you should safeguard the data that you exchange between your app and other applications. Once you complete that, your app’s stability will improve.

It will also enhance the security protection of the data you send and receive. Using signature-based permissions is also great protection.

These permissions will check if the apps accessing the data are signed using the same signing key. It doesn’t require any user confirmation, making it more convenient for you.

Here are other methods you can use;

  • Disallow access to your app’s content providers.
  • Store data in external storage based on the use case.
  • Use WebView objects carefully.
  • Apply network security measures.
  • Use intents to defer permissions.
  • Share data securely across apps.
  • Use HTML message channels.
  • Store private data within internal storage.



Android Apps Google Play Major Flaw Popular Vulnerable 2020-12-04
Noah Gravel
Tags Android Apps Google Play Major Flaw Popular Vulnerable

Author

Posted by : Noah Gravel
Noah is a tech writer for TechVisibility with a passion for tech products.
Previous Article :

Why Huawei Can’t Download Google Apps; Here Are The Best Alternatives

Next Article :

Google Stadia: Is It The New Video Game Revolution?

Related Articles

Instagram Offers Fake Vaccine Cards? Here’s How To Identify Them

Instagram Offers Fake Vaccine Cards? Here’s How To Identify Them

Noah Gravel 02 Sep 2021
Bitcoin Payments Worth $5.2 Billion Linked To Ransomware

Bitcoin Payments Worth $5.2 Billion Linked To Ransomware

Noah Gravel 18 Oct 2021
How to Delete Your Siri Audio History and Prevent Siri Audio Sharing on Mac

How to Delete Your Siri Audio History and Prevent Siri Audio Sharing on Mac

Jody G 29 Jun 2020
Twitter Is Now Indefinitely Suspended In Nigeria

Twitter Is Now Indefinitely Suspended In Nigeria

Maria del Luna 06 Jun 2021
The Phishing Attack On Twilio And Cloudflare Took Employees’ Account Credentials

The Phishing Attack On Twilio And Cloudflare Took Employees’ Account Credentials

Pia Allen 29 Aug 2022
Babbel Language Learning Offers Lifetime Subscription For Only $199

Babbel Language Learning Offers Lifetime Subscription For Only $199

Melissa P 17 Aug 2021

Leave a Reply

  • Facebook Comments
  • Disqus Comments (0)
Specify a Disqus shortname at Social Comments options page in admin panel

Subscribe to our Channel

YouTube Videos

Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo
Youtubevideo /p>

Advertisement


TechVisibility


2493 Technology Drive
Hayward, CA 94545
800-601-4491
contact@techvisibility.com

Follow us

Recent Posts

  • I always guarantee this new pages during the hookup for your requirements never to rating tricked

    Maria del Luna 02 Feb 2023
  • SecretBenefits – A low profile Treasure from inside the Sugar Dating

    Maria del Luna 02 Feb 2023

Advertisement

  • Terms & Conditions
  • Privacy Policy
  • Cookies Policy
  • Accessibility Statement
  • Advertise
  • About Us
  • Contact Us
  • Do not sell my info
  • YouTube Videos
  • My Account
Copyright 2021, All Rights Reserved
Developed By IdealVisibility.com
Posting....
Go to mobile version