Search

AirDroid's Use of Insecure Communication Channels Leaves Users Vulnerable, Claims Zimperium

Advertisement
Highlights
  • AirDroid has been downloaded more than 10 million times from Google Play
  • Vulnerability can potentially allow hacker's to gain users' credentials
  • AirDroid is a remote management tool for Android
AirDroid's Use of Insecure Communication Channels Leaves Users Vulnerable, Claims Zimperium

In the past one year, there have been many critical vulnerabilities regarding Google's mobile platform Android that were exposed by research firms. Now, a mobile security firm has claimed that AirDroid, one of the most popular remote management and file sharing tools on Android, has certain vulnerabilities that can leave its users extremely vulnerable to hacking.

Mobile security firm Zimperium has released details of security vulnerabilities associated with AirDroid that allow hackers on the same network as the user to gain their private information as well as execute code on their phone via malicious APK files.

"AirDroid relies on insecure communication channels in order to send the same data used to authenticate the device to their statistics server. Such requests are encrypted with DES (ECB mode) however the encryption key is hardcoded inside the application itself (thus known to an attacker)," Zimperium said in a note regarding the vulnerability.

According to the security firm, any "malicious party" on the same network as user's device can potentially execute a man-in-the-middle attack and gain access to authentication credentials and impersonate the user to make further requests.

The report further adds that AirDroid's vulnerability allows hackers to even intercept the request sent by the application for add-on updates and therefore make it download a malicious app and make unsuspecting users unknowingly accept the installation request.

Considering that AirDroid has been downloaded more than 10 million times from Google Play, the security flaws can leave a huge number of Android users vulnerable to hack - though of course downloads do not represent active users.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement
Popular Mobile Brands
  1. Vivo X200 FE Compact Smartphone Launched With 6,500mAh Battery
  2. Nothing Phone 3a Pro 5G Long Term Review: A Blend of Style, Speed, and Power
  3. Google Offers to Tweak Search Results to Stave off EU Antitrust Fine
  4. Redmi A4 5G Gets a New RAM and Storage Variant in India
  1. ‘Ghost’ Plume Found Beneath Oman May Explain India’s Ancient Tectonic Shift
  2. Blue Origin’s Crewed Suborbital Launch Delayed Again Due to Weather Conditions
  3. Green Rooftops Could Help Cities Like Shanghai Filter Out Tons of Microplastics from Rainwater
  4. SpaceX to Launch Over 150 Memorial DNA Capsules into Orbit on Celestis’ Perseverance Flight
  5. Rubin Observatory to Unveil First Cosmic Images with World’s Largest Digital Camera
  6. The Gilded Age OTT Release: Where to Watch This HBO Original Series
  7. Cleaner (2025) OTT Release Date: When and Where to Watch it Online?
  8. Yugi Now Available for Streaming on Aha Tamil: Everything You Need to Know
  9. Samsung Exynos 2500 SoC With Up to 15 Percent Improved CPU Performance, Xclipse 950 GPU Launched
  10. Vivo X200 FE With 6,500mAh Battery, MediaTek Dimensity 9300+ SoC Launched: Specifications
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »