“New” security hole affects 99 percent of Android users



A newly discovered security hole could affect as much as 99 percent of the Android userbase. According to security researchers at Bluebox Labs, a bug that has existed since Android 1.6 allows for third-party sources to modify an application without breaking its cryptographic signature. Translated, this means a hacker could theoretically push malware to a device in the form of an update to an app legitimately installed on a handset.

There would still be a few hurdles to clear to make this a reality, such as devising a means to deliver the update to a user’s handset. It would not be possible through the Google Play Store, but could possibly be achieved through a third-party app store or bogus website. If a hacker could trick users into installing the disguised malware, they would have free reign to deploy any number of existing or new Android trojans.

Bluebox has already alerted Google, but it seems there is little being done. The Android maker is leaving it to device manufacturers to address the issue, which is apparently the case with Samsung. Word is they have patched the issue with the Galaxy S4. Google’s Nexus 4, on the other hand, remains vulnerable.

[via The Verge]

Kevin Krause
    6. There’s exploits for iOS just the same. If it can be jailbroken, it can be exploited. Don’t get yourself into a false sense of security. I remember a hack off challenge between a Mac, a PC running Windows 7, and Linux. The hacker was able to crack the Mac the easiest and the fastest. Linux took the longest to crack.

  Read more than the headlines people: "How that distribution would actually occur is still theoretical. Exploiting via Google's Play Store isn't possible, since Google has already updated the platform." You could only get this if you choose to use third party sites. Unlike apple you have choices with Android. And the choices include you can knowingly do the wrong thing by digging deep into settings and allowing "install from unknown sources" and actively searching for unknown places to download unknown software packages.

    Yup, so for us users that don't tinker with third party sites .. this article is pointless

      Couldn't agree more. Use only the Play Store, Amazon App Store and your brain.

        Amazon app store is vulnerable as well, you have to have unknown sources permission to use it.

    That's the reason there's choice, you can't let fanboyism cloud reality, the threat is real, now that it's known ,every malicious hacker will try to exploit this, in so many different forms. These other app stores have to step up their game, if not leave them alone(I know I will, I'm not lame enough to just forget about the risk). Google , must have known about this years ago, how it's explained makes a lot of sense, if I hacked, I'd find a way to use it.

      No one is saying that the threat isn't real but these tech sites are exaggerating the extent of this threat. Taking into consideration that most people DON'T side load apps or even know what "apk" means, this does not affect 99% of users.

      Who doesn't know that downloading things from unknown sources can have serious consequences? People who are choosing to side load apps already know the danger and they still do it. Why are you worried about them if they're not?

  Saying this is a security hole in Android is like saying cars force us to break the law because we can choose to go faster than the posted speed limit.

    It's a simple process to not allow installations from unknown sources. Calling this a security hole is disingenuous and frankly untrue. The user is warned twice when checking this option.

      Do you really understand how little this affects the hundreds of millions of Android users? First, you have to have "Unknown sources" checked. Most people don't even know it's a setting they can enable/disable. If it's not check marked, this vulnerability doesn't apply to you. There goes several million Android devices alone.

        Secondly, you would have to go outside of the Play Store as everything contained within is safe from this vulnerability. Again, not many people know or care about 3rd party app stores. What's easiest is usually the best. So again, knock off a handful more million Android devices.

        Thirdly, it is possible that this could affect Amazon's app store and a few others like it, but unlikely. You're more likely to get a "cracked" app from some Chinese source that sells paid apps for free (pirating), in which case, you get what you deserve. And just because I sideloaded an app from XDA does not automatically mean I'm infected/vulnerable, since XDA is for the most part, pretty safe.

        Fourthly, Bluebox discovered a vulnerability. They didn't discover an app in the wild that actually does this. Sure, someone could come along and make said app, but for the reasons stated above, the likelihood of it affecting anyone is nil.

        You are going out of your way to use apps outside the recommended and preferred ecosystem.

        Do I need to mention the plethora of security risks when Jailbreaking an iOS device. It's no different on Android. The title of the article is a bit misleading and that's what the OP was trying to say.

  The really stupid part here is that the risk comes from installing an app from an untrustworthy source. The thing is if the risk here is from such a source then installing it in the first place is a problem! Because it could have just as easily been a malicious app upon initial install. News sites are running around screaming about this but really a non-story. Until someone can hijack official google market updates (without needing to hack into a dev's account…because in that case you could just put your malicious code into a normal update) then I don't can fathom how this is dangerous.

    The only time I sideload anything, is when I get unsupported apk's for rooting purposes, that I know google play won't allow(usually by pc). I leave other appstores alone anyway, they only seem to interested in games, and other frivolous things. I do much better getting what I need thru the pc. I scan it first thru the pc's antivirus, then I run it thru my avd manager. If it passes that, I install. There's no reason the alternative appstores don't check what they put out, it makes good business sense.

  Fortunately there's an article about it on Android Central based on fact, written with actual skill.

      2. Is THAT a joke? The AC article he’s referencing has at least 4x the amount of words, that go much much further in depth on the issue, along with presenting possible remedies/solutions. Hell, their explanation of what it is alone is longer than this “article”, and presents none of the doom-and-gloom that Kevin and most other sites that reported on this seem to think there is.

        Yes, it affects 99% of all Android devices, IF you get your apps from somewhere other than the Play Store, AND if you have that “Unknown Sources” checked, AND if you’re stupid enough install an app from some shady/unverified source. That effectively puts the percentage of people this affects at maybe 10%, more than likely less. Also, considering the average Android user has no idea that you can sideload apps, let alone that there’s a checkbox to enable it, makes this basically a non issue.

  Want to know something strange on a diffrent site last night I read this article and the comment section lit up and the "writer" of that article was a Ios user. as I read through the comments they mirrior each other, even tho google handled it in febuary

  It might possibly affect "99% of devices" IF you download from places other than the Play Store, and are a complete and total idiot. Most people don't even know there's a checkbox to allow sideloading of apps.

    Just another FUD piece by none other than iPhone loving Kevin Krause. If you want something infinitely more detailed and less doom-and-gloom, go read Android Central's article on this same topic: http://www.androidcentral.com/making-sense-latest-android-security-scare

    1. “It might possibly affect “99% of devices” IF you download from
      places other than the Play Store, and are a complete and total idiot.
      Most people don’t even know there’s a checkbox to allow sideloading of

      Yes exactly! Ask any casual user what "side loading" means and how many will know the answer?

  I see dozens of headlines similar to this one on Google News. A more accurate (but less dramatic) headline might be "Users of third-party Android app stores are affected by security flaw."

  Not only is this just an issue for side loading third party apps, but to be a really significant threat, it would have to be a sideloaded app with root level permissions. 99% indeed.

  Overstated, this only affects people who sideload and install apps from outside Google Play, while a number of users on phandroid might do that, overall most Android users do not install apps from unknown sources. It's an issue, no doubt that is being remedied but by patching the google play store (which is already done) I actually effectively solves the problem for the vast majority of people already, unknown sources has always been kind of dangerous. I use it occasionally myself but you have to be careful.

  The only apps I've ever side loaded were adblock and adobe flash. Got both from xda devs which I trust.

  So great that this information could help us a lot about android phones. Nowadays, many android phone online store that sell different android phone brands. Only there is the description and no satisfactorily information to broaden our knowledge about iphones. Thanks to this site!

