99% of Android apps vulnerable to attackers without breaking signatures

Published July 5, 2013
Android Developers Conference 28 june 2012. — Reuters Photo
Android Developers Conference 28 june 2012. — Reuters Photo

The Android operating system has been vulnerable to hackers for the past four years, allowing them to modify or manipulate any legitimate application and enabling them to transform it into a Trojan program.

These Trojan programs can further be used to steal data or take control of the OS.

Researchers at Bluebox Security, a mobile security startup firm in San Francisco, uncovered the flaw and will be addressing the issue in detail at the Black Hat USA security conference in Las Vegas in coming weeks.

The vulnerability identified by the Bluebox researchers effectively allows attackers to add malicious code to already signed application packages (APKs) without breaking their signatures.

When an application is installed and a sandbox is created for it, Android records the application's digital signature, said Bluebox Chief Technology Officer Jeff Forristal. All subsequent updates for that application need to match its signature in order to verify that they came from the same author, he said.

The vulnerability has existed since at least Android 1.6, code named Donut, which means that it potentially affects any Android device released during the last four years, the Bluebox researchers said in a blog post.

"Depending on the type of application, a hacker can exploit the vulnerability for anything from data theft to creation of a mobile botnet," they said.

Opinion

Editorial

IMF’s projections
Updated 18 Apr, 2024

IMF’s projections

The problems are well-known and the country is aware of what is needed to stabilise the economy; the challenge is follow-through and implementation.
Hepatitis crisis
18 Apr, 2024

Hepatitis crisis

THE sheer scale of the crisis is staggering. A new WHO report flags Pakistan as the country with the highest number...
Never-ending suffering
18 Apr, 2024

Never-ending suffering

OVER the weekend, the world witnessed an intense spectacle when Iran launched its drone-and-missile barrage against...
Saudi FM’s visit
Updated 17 Apr, 2024

Saudi FM’s visit

The government of Shehbaz Sharif will have to manage a delicate balancing act with Pakistan’s traditional Saudi allies and its Iranian neighbours.
Dharna inquiry
17 Apr, 2024

Dharna inquiry

THE Supreme Court-sanctioned inquiry into the infamous Faizabad dharna of 2017 has turned out to be a damp squib. A...
Future energy
17 Apr, 2024

Future energy

PRIME MINISTER Shehbaz Sharif’s recent directive to the energy sector to curtail Pakistan’s staggering $27bn oil...