Android App Permission in Google Play Contains Security Flaw
Android's app permission mechanisms could allow malicious apps in Google Play to download directly onto the device.
Security researchers discovered a security vulnerability in Android's app permission model that could allow malicious apps to download onto the mobile device directly from Google Play and launch ransomware, adware, and banking malware, according to a Check Point Software blog post today.
Check Point found the flaw in Android version 6.0.0., otherwise known as the Marshmallow.
"As a temporary solution, Google applied a patch in Android version 6.0.1 that allows the Play Store app to grant run-time permissions, which are later used to grant SYSTEM_ALERT_WINDOW permission to apps installed from the app store. This means that a malicious app downloaded directly from the app store will be automatically granted this dangerous permission," Check Point wrote in a blog post today.
The SYSTEM-ALERT-WINDOW mechanism will also effectively bypass security mechanisms introduced in the previous version of Android, according to Check Point.
Google plans to fix the issue in its upcoming "Android 0" version.
Read more about the Android vulnerability here.
About the Author(s)
You May Also Like
Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024