Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

2/23/2016
04:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Leaky Apps Far Riskier Than Mobile Malware

Even top enterprise apps are rampant with data leakage and privacy-invasive behavior.

Mobile malware may be the most intriguing thing to capture the attention of mobile-minded security researchers today. But according to a report out today by Appthority, the bigger risks statistically come from misbehaving legitimate apps.

The Appthority Enterprise Mobile Threat Team's quarterly Mobile Threat Report took a deep dive look into some of the most recent threats on the mobile app landscape. While significant iOS exploits like XcodeGhost, YouMi, and MobiSage certainly raised eyebrows, the researchers found that a risk analysis across the entire app ecosystem showed that these and other malware risks are eclipsed by data leakage and privacy invasive behaviors from otherwise legitimate applications.   

"While Apple and Google generally do a great job of reviewing apps for overall risk, they are mainly trying (sometimes unsuccessfully) to keep malware out of the app stores and are not monitoring apps for other enterprise risks like data exfiltration and privacy invasive behaviors," the report explained.

Some of the data leak behaviors include sending out or broadcasting unique device identifiers, address book, calendar, location or SMS messages, attempting to root a device or capabilities for recording calls, or other user-initiated activity. Privacy invasive activity includes tracking locations, accessing address book, calendar, SMS archives, microphone and other functions, and sending data to ad networks.

In examining over 315,000 unique iOS and Android apps from the respective platform's app stores, Appthority found that just over 48% of iOS apps and nearly 87% of Android apps displayed data leakage behaviors.

Meanwhile over 62% of iOS and 86% of Android apps engage in privacy invasive behavior. Even these behaviors pose risks to enterprises.

"For example, if an app is leaking employee address book data, it will be much easier for attackers to user the information collected from the address book to launch a targeted spear phishing, malware or other cyber attack," the report explains.

Interestingly, enterprise apps are no better in this department--in fact, they're just a tick more risky. Of the 100,000 apps already in enterprise mobile ecosystems or being pre-evaluated for risk to be entered in this enterprise app pool, nearly 50% of iOS apps and over 88% of Android apps display data leakage behaviors, and over 65% of iOS apps and 88% of Android apps engage in privacy invasive behaviors. Narrow that down to the top 150 apps in the enterprise and these numbers go up significantly, by as much as 30 percentage points.

Clearly, enterprises are facing an uphill battle with vetting these applications.

"Even if an enterprise were to focus on trying to whitelist the top 150 most popular apps, each of these apps may see up to 10 new versions per year, creating a bottleneck in the review and approval process," the report says.

 

Interop 2016 Las VegasFind out more about mobile security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11529
PUBLISHED: 2020-04-04
Common/Grav.php in Grav before 1.6.23 has an Open Redirect.
CVE-2020-11527
PUBLISHED: 2020-04-04
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
CVE-2020-11528
PUBLISHED: 2020-04-04
bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.
CVE-2020-11518
PUBLISHED: 2020-04-04
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
CVE-2020-5347
PUBLISHED: 2020-04-04
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.