Android Installer Vulnerability Affecting 49.5 Percent of Devices: Report

Advertisement
By NDTV Correspondent | Updated: 26 March 2015 14:05 IST

Security researchers at Palo Alto Networks claim to have found a vulnerability in Android versions ranging from v2.3 (Gingerbread) to v4.3_r0.9 (Jelly Bean) that allows attackers to gain full access to compromised devices. The bug pertains to the fact that in vulnerable versions of Android there are no checks at the time of installation of whether an app's permissions actually match those advertised to the user during installation. The vulnerability only affects apps installed from third-party app stores.

Palo Alto Networks says the vulnerability, which it is calling Android Installer Hijacking, is of the 'Time-of-Check to Time-of-Use (TOCTTOU)' type, and allows attackers to mask the permissions of an app being installed between the check page (which lists the permissions) and the actual installation of the apk file.

Advertisement

Essentially, the system service PackageInstaller on affected devices does not verify the apk file at the time of installation, only prior to displaying the permissions - this means the app installed can have different permissions from what are shown. This could allow access to user data including passwords.

The firm says as of Google's March 2015 Android distribution numbers, affected devices account for roughly 49.5 percent of active Android devices. Palo Alto Networks adds that back in January 2014 when it discovered the vulnerability, which it is calling Android Installer Hijacking, the security flaw affected 89.4 percent of active Android devices.

Advertisement

In February last year however, Palo Alto Networks says it informed Google's Android Security Team, and then informed Samsung in March, and Amazon (the vulnerability includes devices accessing Amazon Appstore for Android) in September, so that patches could be issued.

A quote by the Google team on the security firm's blog post says, "Android Open Source Project includes patches for this issue for Android 4.3 and later," and adds that the Team "has not detected any attempts to exploit this vulnerability on user devices."

Advertisement

Amazon on the other hand recommends users should download the latest version of the Amazon Appstore for Android, which it says gets "updated automatically on Fire devices and for 3rd party Android devices it can be updated via www.amazon.com/getappstore."

Palo Alto Networks itself has released an app to the Google Play store that allows users to check if their devices are affected by the Android Installer Hijacking vulnerability. It adds that Samsung and Amazon have released fixes for their affected devices, which included those running on Fire OS.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Mivi One 5G Camera Details Revealed Ahead of India Launch
  2. Apple 18 Pro Max Manages Full Charge Faster Than iPhone 17 Pro Max, Video Reveals
  3. Xiaomi 18 Pro Max Specifications Revealed by Geekbench Listing
  4. Here's When Apple Pay Could Launch in India
  5. Bose Sport Open Earbuds, Ultra Open Earbuds (2nd Gen) Debut: Price, Features
  6. Samsung Gallery Reportedly Gets Google Photos Sync Feature
  7. OnePlus 13s Gets a New 16GB RAM Option in India at This Price
  8. Samsung Galaxy S26 Series Price Hike Not Happening Anytime Soon
  9. Google Pixel Drop September 2026 Adds Harry Potter Audiobook Packs and More
  1. TRAI Adds New Rules for Spam Calls, Automated Calls and A2P Communications
  2. Meta Muse AI Agent Arrives on Mac With Support for Complex Tasks: What to Know
  3. WhatsApp Could Bring New Theme Categories and Wallpapers to Android
  4. Mivi One 5G Camera Details Revealed, Mivi Care+ Support Teased Ahead of Launch
  5. OpenAI Gets Hacked by Indian-Origin Ethical Hackers Using Anthropic’s Claude
  6. OpenAI Announces Astra for Law With GPT-6 Astra, Legal Search Index and Specialist Plugins
  7. Google Gemini Live Could Get an Ephemeral Video Mode for More Private AI Sessions
  8. Apple Pay Could Launch in India Next Month With Axis Bank Credit Cards, Report Claims
  9. Samsung Gallery Adds Google Photos Integration Ahead of OneDrive Sync Ending: How It Works
  10. BenQ Showcases New iScreenBar and ScreenBar Max Desk Lighting Systems at InfoComm 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.