Search

Android Installer Vulnerability Affecting 49.5 Percent of Devices: Report

Advertisement
Android Installer Vulnerability Affecting 49.5 Percent of Devices: Report

Security researchers at Palo Alto Networks claim to have found a vulnerability in Android versions ranging from v2.3 (Gingerbread) to v4.3_r0.9 (Jelly Bean) that allows attackers to gain full access to compromised devices. The bug pertains to the fact that in vulnerable versions of Android there are no checks at the time of installation of whether an app's permissions actually match those advertised to the user during installation. The vulnerability only affects apps installed from third-party app stores.

Palo Alto Networks says the vulnerability, which it is calling Android Installer Hijacking, is of the 'Time-of-Check to Time-of-Use (TOCTTOU)' type, and allows attackers to mask the permissions of an app being installed between the check page (which lists the permissions) and the actual installation of the apk file.

Essentially, the system service PackageInstaller on affected devices does not verify the apk file at the time of installation, only prior to displaying the permissions - this means the app installed can have different permissions from what are shown. This could allow access to user data including passwords.

The firm says as of Google's March 2015 Android distribution numbers, affected devices account for roughly 49.5 percent of active Android devices. Palo Alto Networks adds that back in January 2014 when it discovered the vulnerability, which it is calling Android Installer Hijacking, the security flaw affected 89.4 percent of active Android devices.

In February last year however, Palo Alto Networks says it informed Google's Android Security Team, and then informed Samsung in March, and Amazon (the vulnerability includes devices accessing Amazon Appstore for Android) in September, so that patches could be issued.

A quote by the Google team on the security firm's blog post says, "Android Open Source Project includes patches for this issue for Android 4.3 and later," and adds that the Team "has not detected any attempts to exploit this vulnerability on user devices."

Amazon on the other hand recommends users should download the latest version of the Amazon Appstore for Android, which it says gets "updated automatically on Fire devices and for 3rd party Android devices it can be updated via www.amazon.com/getappstore."

Palo Alto Networks itself has released an app to the Google Play store that allows users to check if their devices are affected by the Android Installer Hijacking vulnerability. It adds that Samsung and Amazon have released fixes for their affected devices, which included those running on Fire OS.

Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. A New Greece-Set God of War Game Is Reportedly Coming This Year
  2. Vivo T4 5G India Launch Timeline, Price Range, Key Features Leaked
  3. iQOO Z10 Teased to Have a Thin Profile; to Be Available on Amazon
  4. Poco F7 India Launch Timeline, Chipset Details Tipped Online
  5. Motorola Edge 60 Fusion India Launch Date, Design, Key Features Revealed
  6. Apple's Foldable iPhone Could Launch in 2026 With iPhone 17 Air Technology
  7. Realme Narzo 80 Pro 5G to Launch in India Soon; Will Use This New Chipset
  8. Infinix Note 50X 5G Confirmed to Offer IP64 Rating Ahead of India Launch
  1. Indiana Jones and the Great Circle's PS5 Release Date Will Reportedly Be Announced on March 24
  2. Headphone Zone X Oriveti Blackbird In-Ear Monitor Launched in India: Price, Specifications
  3. Tamil Nadu DGP Unveils ‘Handbook for Investigations into Virtual Digital Assets’: All Details
  4. Poco F7 India Launch Timeline Leaked; Tipped to Feature Snapdragon 8s Elite Chipset
  5. Nvidia Releases Cosmos-Transfer1 AI Model That Can Be Used for Simulation-Based Training for Robots
  6. Vivo T4 5G Could Launch in India in April; Price Range, Key Features Surface Online
  7. Adobe Previews Multiple New AI Agents-Driven Enterprise Tools for Complex Data Analysis
  8. Realme Narzo 80 Pro 5G Teased to Launch in India Soon; Will Be Equipped With MediaTek Dimensity 7400 SoC
  9. Android 16 Developer Preview 3 Reportedly Enables Screen-Off Fingerprint Unlock on All Pixel Phones
  10. iQOO Z10 Teased to Measure 7.89mm in Thickness; to Be Available on Amazon
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »