Android Installer Vulnerability Affecting 49.5 Percent of Devices: Report

Advertisement
By NDTV Correspondent | Updated: 26 March 2015 14:05 IST

Security researchers at Palo Alto Networks claim to have found a vulnerability in Android versions ranging from v2.3 (Gingerbread) to v4.3_r0.9 (Jelly Bean) that allows attackers to gain full access to compromised devices. The bug pertains to the fact that in vulnerable versions of Android there are no checks at the time of installation of whether an app's permissions actually match those advertised to the user during installation. The vulnerability only affects apps installed from third-party app stores.

Palo Alto Networks says the vulnerability, which it is calling Android Installer Hijacking, is of the 'Time-of-Check to Time-of-Use (TOCTTOU)' type, and allows attackers to mask the permissions of an app being installed between the check page (which lists the permissions) and the actual installation of the apk file.

Advertisement

Essentially, the system service PackageInstaller on affected devices does not verify the apk file at the time of installation, only prior to displaying the permissions - this means the app installed can have different permissions from what are shown. This could allow access to user data including passwords.

The firm says as of Google's March 2015 Android distribution numbers, affected devices account for roughly 49.5 percent of active Android devices. Palo Alto Networks adds that back in January 2014 when it discovered the vulnerability, which it is calling Android Installer Hijacking, the security flaw affected 89.4 percent of active Android devices.

Advertisement

In February last year however, Palo Alto Networks says it informed Google's Android Security Team, and then informed Samsung in March, and Amazon (the vulnerability includes devices accessing Amazon Appstore for Android) in September, so that patches could be issued.

A quote by the Google team on the security firm's blog post says, "Android Open Source Project includes patches for this issue for Android 4.3 and later," and adds that the Team "has not detected any attempts to exploit this vulnerability on user devices."

Advertisement

Amazon on the other hand recommends users should download the latest version of the Amazon Appstore for Android, which it says gets "updated automatically on Fire devices and for 3rd party Android devices it can be updated via www.amazon.com/getappstore."

Palo Alto Networks itself has released an app to the Google Play store that allows users to check if their devices are affected by the Android Installer Hijacking vulnerability. It adds that Samsung and Amazon have released fixes for their affected devices, which included those running on Fire OS.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Honor's MagicOS 11 Could Be Android's Closest Take on Apple's Liquid Glass
  2. Telecos Reportedly Oppose TRAI Proposal on Cheaper Voice and SMS Packs
  3. You Can Now Download Android 17 on These Devices
  4. The OnePlus 15R Is Now Available in a New 16GB RAM Variant at This Price
  5. Epson Expands EcoTank Portfolio in India With 15 New Printer Models
  6. Tim Cook Says Apple Can No Longer Absorb Soaring Memory Costs Alone
  7. iPhone 18 Pro Max Could Fit Existing iPhone 17 Pro Max Cases
  8. OnePlus N6 Confirmed to Launch in India With an 8,000mAh Battery
  9. ChatGPT's Grip on AI Assistant Market Weakens Despite Record User Base
  10. Samsung Galaxy Z Fold 8 Series Might Debut at a Higher Price Than Fold 7
  1. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order in Select Markets: Price, Features
  2. Honor Teases MagicOS 11 Update With Liquid Glass-Inspired Design as Early Access Programme Kicks Off
  3. Samsung Galaxy Z Fold 8 Series Tipped to Launch at Higher Price Than Last Year’s Galaxy Z Fold 7
  4. ChatGPT’s Market Share Falls Below 50 Percent for First Time as Gemini, Claude Gain Ground: Report
  5. Apple May Reportedly Raise iPhone, Mac Prices Amid Memory Chip Shortage, Tim Cook Says
  6. Scientists Discover Giant Planet Formation Around Supermassive Black Holes
  7. EA Sports FC 26, Call of Duty: Vanguard and More Coming to Xbox Game Pass This Month
  8. Vivo Y500 4G Global Launch Teased; Confirmed to Debut With 8,100mAh Battery
  9. WhatsApp Working on Voice Note Widget for Quick Access via Android Home Screen
  10. Honor X80 Pro Max Teased With 10,000 Nits Display Ahead of June 22 Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.