Backend Vulnerabilities Found in Top 5,000 Free Android Apps: Report

Researchers from Georgia Institute of Technology and The Ohio State University studied only applications in the Google Play Store.

Advertisement
By Indo-Asian News Service | Updated: 13 August 2019 19:14 IST
Highlights
  • The vulnerabilities were found in the backend systems
  • 655 instances of zero-day vulnerabilities spotted
  • The researchers have created an automated system to help developers

Researchers discovered 983 instances of known vulnerabilities on apps listed on Google Play Store

Cybersecurity researchers have identified more than 1,600 vulnerabilities in the support ecosystem behind the top 5,000 free apps available in the Google Play Store.

While the researchers from Georgia Institute of Technology and The Ohio State University studied only applications in the Google Play Store, applications designed for iOS may share the same backend systems.

The vulnerabilities were found in the backend systems that feed content and advertising to smartphone applications through a network of Cloud-based servers.

Advertisement

The vulnerabilities, affecting multiple app categories, could allow hackers to break into databases that include personal information - and perhaps into users' mobile devices, said the study scheduled to be presented at the 2019 USENIX Security Symposium in the US on Thursday.

Advertisement

"These vulnerabilities affect the servers that are in the cloud, and once an attacker gets on the server, there are many ways they can attack," said Brendan Saltaformaggio, Assistant Professor in Georgia Tech's School of Electrical and Computer Engineering.

The researchers were still investigating whether attackers could get into individual mobile devices connected to vulnerable servers.

Advertisement

"It's a whole new question whether or not they can jump from the server to a user's device, but our preliminary research on that is very concerning," Saltaformaggio added.

In their study, the researchers discovered 983 instances of known vulnerabilities and another 655 instances of zero-day vulnerabilities spanning across the software layers - operating systems, software services, communications modules and web apps - of the Cloud-based systems supporting the apps.

Advertisement

To help developers improve the security of their mobile apps, the researchers have created an automated system called SkyWalker to vet the Cloud servers and software library systems.

SkyWalker can examine the security of the servers supporting mobile applications, which are often operated by Cloud hosting services rather than individual app developers.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo V70, Vivo V70 Elite Price in India Leaked Ahead of Launch
  2. Asus Zenbook 14 (UM3406G) Review: A Premium Thin-and-Light That Delivers
  3. NASA Successfully Tests Drag-Reducing Laminar-Flow Wing in Flight
  4. Apple's Latest iPhone Update Makes It Easier to Switch from an Android
  5. Xiaomi 17, Xiaomi 17 Ultra India Price Leaked; May Rival Samsung, Apple
  6. Hubble Reveals Dramatic Final Moments of a Sun-Like Star in the Egg Nebula
  7. Vivo X300 Max Listed on 3C Database; Key Features, Launch Timeline Leaked
  8. Oppo Find X9 Ultra Leak Suggests Big Battery Upgrade Over the Find X8 Ultra
  1. NASA Successfully Tests Drag-Reducing Laminar-Flow Wing in Flight
  2. Hubble Reveals Dramatic Final Moments of a Sun-Like Star in the Egg Nebula
  3. Xiaomi 17, Xiaomi 17 Ultra Price in India Leaked; May Rival iPhone 17, Samsung Galaxy S25 Series Models
  4. Kingdom Come: Deliverance 2 Has Sold 5 Million Copies, Warhorse Studios Confirms
  5. Boys of Tommen OTT Release Confirmed: Where to Watch to This Upcoming Irish Romance Drama Online?
  6. Medical Dialogues Wins Google-Backed JournalismAI Innovation Challenge
  7. Ikkis Now Available for Rent on Amazon Prime Video: What You Need to Know About Arun Khetarpal Biopic
  8. HP Launches New DeskJet Ultra Ink Advantage, DeskJet Ink Advantage All-in-One Printers in India: Price, Features
  9. Nike Domain 3 Cricket Footwear Launched in India With React Foam and Stability-Focused Design
  10. Lava Yuva Star 3 Launched in India With 5,000mAh Battery, 6.75-Inch Display: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.