99% of Android apps vulnerable to attackers without breaking signatures

Published July 5, 2013
Android Developers Conference 28 june 2012. — Reuters Photo
Android Developers Conference 28 june 2012. — Reuters Photo

The Android operating system has been vulnerable to hackers for the past four years, allowing them to modify or manipulate any legitimate application and enabling them to transform it into a Trojan program.

These Trojan programs can further be used to steal data or take control of the OS.

Researchers at Bluebox Security, a mobile security startup firm in San Francisco, uncovered the flaw and will be addressing the issue in detail at the Black Hat USA security conference in Las Vegas in coming weeks.

The vulnerability identified by the Bluebox researchers effectively allows attackers to add malicious code to already signed application packages (APKs) without breaking their signatures.

When an application is installed and a sandbox is created for it, Android records the application's digital signature, said Bluebox Chief Technology Officer Jeff Forristal. All subsequent updates for that application need to match its signature in order to verify that they came from the same author, he said.

The vulnerability has existed since at least Android 1.6, code named Donut, which means that it potentially affects any Android device released during the last four years, the Bluebox researchers said in a blog post.

"Depending on the type of application, a hacker can exploit the vulnerability for anything from data theft to creation of a mobile botnet," they said.

Opinion

Budgeting without people

Budgeting without people

Even though the economy is a critical issue, discussions about it involve a select few who are not really interested in communicating with the people.

Editorial

Iranian tragedy
Updated 21 May, 2024

Iranian tragedy

Due to Iran’s regional and geopolitical influence, the world will be watching the power transition carefully.
Circular debt woes
21 May, 2024

Circular debt woes

THE alleged corruption and ineptitude of the country’s power bureaucracy is proving very costly. New official data...
Reproductive health
21 May, 2024

Reproductive health

IT is naïve to imagine that reproductive healthcare counts in Pakistan, where women from low-income groups and ...
Wheat price crash
Updated 20 May, 2024

Wheat price crash

What the government has done to Punjab’s smallholder wheat growers by staying out of the market amid crashing prices is deplorable.
Afghan corruption
20 May, 2024

Afghan corruption

AMONGST the reasons that the Afghan Taliban marched into Kabul in August 2021 without any resistance to speak of ...
Volleyball triumph
20 May, 2024

Volleyball triumph

IN the last week, while Pakistan’s cricket team savoured a come-from-behind T20 series victory against Ireland,...