Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Tech News > Android vulnerability enables attacks over open Wi-Fi networks

Android vulnerability enables attacks over open Wi-Fi networks
Thread Tools
MacNN Staff
Join Date: Jul 2012
Status: Online
Reply With Quote
Sep 27, 2013, 12:14 PM
 
Researchers have reportedly discovered a new Android vulnerability that potentially affects a large number of devices. The issue is said to be directly related to the WebView programming interface, used for web-based features within native apps. Some Android apps reportedly fail to properly secure data as it is transferred between the Internet and the app's WebView feature, leaving the device open to attack by someone else on the same Wi-Fi network.

"The lowest impact attack would be downloading contents of the SD card and the exploited application's data directory," research firm MWR InfoSecurity wrote in an advisory that was spotted by Ars Technica
The researchers suggest many Android apps are using older versions of SDKs for advertising networks, serving as a vulnerable route for man-in-the-middle attacks. Taking a close look at the top 100 apps in the Play Store, 62 were found to be "potentially" vulnerable to such attacks.

Despite the reports, Android's other security restrictions are said to serve as further protection against malicious code that is injected using the WebView vulnerability. Google also improved security with Android 4.2, providing more tools for developers to protect against such attacks.

Due to the software upgrade delays for most Android phones, an immediate resolution would require developers to update their apps with proper implementation of SSL encryption for WebView data.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -4. The time now is 06:37 PM.
All contents of these forums © 1995-2015 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2015, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2