Android's app permission mechanisms could allow malicious apps in Google Play to download directly onto the device.
Security researchers discovered a security vulnerability in Android's app permission model that could allow malicious apps to download onto the mobile device directly from Google Play and launch ransomware, adware, and banking malware, according to a Check Point Software blog post today.
Check Point found the flaw in Android version 6.0.0., otherwise known as the Marshmallow.
"As a temporary solution, Google applied a patch in Android version 6.0.1 that allows the Play Store app to grant run-time permissions, which are later used to grant SYSTEM_ALERT_WINDOW permission to apps installed from the app store. This means that a malicious app downloaded directly from the app store will be automatically granted this dangerous permission," Check Point wrote in a blog post today.
The SYSTEM-ALERT-WINDOW mechanism will also effectively bypass security mechanisms introduced in the previous version of Android, according to Check Point.
Google plans to fix the issue in its upcoming "Android 0" version.
Read more about the Android vulnerability here.
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024