Techno-News Blog

July 16, 2013

Google patches critical Android threat as working exploit is unleashed

Filed under: Uncategorized — admin @ 12:15 am

by Dan Goodin, arstechnica

A security researcher has published working exploit code that allows attackers to surreptitiously turn legitimate apps running on Google’s Android mobile operating system into malicious trojans. Around the same time, Google said it released a patch that helps protect users from abuse. As previously reported, the weakness involves the way legitimate Android applications are cryptographically signed to ensure they haven’t been modified by parties other than the trusted developer. Researchers at security startup Bluebox provided high-level details of the vulnerability last week, but omitted technical details most people would need to reproduce the attack. That didn’t stop members of CyanogenMod, an alternative Android firmware version, from piecing together the available details into this bug report that identifies the conditions necessary for exploiting the vulnerability. It also incorporates a fix from Google into the CyanogenMod code.

http://arstechnica.com/security/2013/07/google-patches-critical-android-threat-as-working-exploit-is-unleashed/

Share on Facebook

No Comments

No comments yet.

RSS feed for comments on this post. TrackBack URL

Sorry, the comment form is closed at this time.

Powered by WordPress