A loophole which makes Android vulnerable to hackers

A ‘master key’ has been reportedly discovered by a security research firm which could potentially give cyberattackers access to almost every Android phone.

According to BBC, security research firm BlueBox has discovered the loophole which is present in every version of the Android operating system released since 2009.

The bug emerges as a result of the way Android handles cryptographic verification of the programs installed on the phone

The report said that Android uses the cryptographic signature as a way to check that an app or program is legitimate and to ensure it has not been tampered with.

Jeff ForristalBlueBox and his colleagues have found a method of tricking the way Android checks these signatures so that malicious changes to the apps go unnoticed.

Forristal said that the implications of this discovery could be ‘huge’ as it can take over the normal functioning of the phone and control any function thereof.

Security expert Dan Wallach said that in order to catch Android users, malicious hackers would have to get their booby-trapped version of a legitimate application on to the Google Play store.

According to the report, BlueBox had reported finding the bug to Google in February.

Google denied commenting on BlueBox discovery, the report added.

Via: TOI

Image Credit: AndroidTwit

 

Team TechPanda

Recent Posts

Can you trust AI with your fundraising secrets?

A founder’s guide to data privacy in the age of GenAI AI has shifted from…

4 days ago

Can India be a South Asian tech titan in the making?

India has been embracing technology at a high rate. The world has expectations from the…

5 days ago

Building tomorrow’s offices: Blending aesthetics with automation, sensors & sustainability

In a world where the lines between physical and digital experiences are increasingly blurred, the…

5 days ago

For medical research & doctors AI has been a good team player

No matter what other controversy Artificial Intelligence (AI) might be getting into, AI has been…

6 days ago

UTI Mutual Fund warns against fake app & WhatsApp scams

The UTI Mutual Fund has said that it has observed that some groups, individuals, handles…

6 days ago

Starlink Satellites go to India: IN-SPACe grants authorization to Starlink Satellite Communications Pvt Ltd

Indian National Space Promotion and Authorization Centre (IN-SPACe) has granted authorization to M/s Starlink Satellite…

6 days ago