Android Devices Running Versions Below Android 9.0 Pie Vulnerable to Tracking by Apps: Researchers

Advertisement
By Sumit Chakraborty | Updated: 4 September 2018 18:33 IST
Highlights
  • Newly discovered Android security flaw can be used to track users
  • The vulnerability can expose details to all the apps in your device
  • Google apparently fixed the flaw with Android 9.0 Pie only

Researchers say Android devices are vulnerable to the security issue, except those running Android Pie

Researchers have pointed out an Android security flaw that apparently exposes details about a user's device to all applications running on the device. Google has provided a fix for it in its latest Android version - Android Pie - but older versions are still vulnerable to the issue, researchers claim. The vulnerability essentially allows apps to move past permissions to get access to information found in system broadcasts. It includes details such as the name of the Wi-Fi network that the Android device is using, the MAC address of the device, local IP addresses, BSSID, and DNS server information. All of this leaves the devices easy to locate and track.

The Android security flaw (CVE-2018-9489) was found by researchers from Nightwatch Cybersecurity, who have warned that the vulnerability can be used to "uniquely identify and track any Android device" and also to "geolocate users". While the advisory mentions all the information that the apps can access, it also states that some of the details such as MAC address are no longer available via APIs on Android 6 and higher. Also, extra permissions are usually required to get access to such information. However, the report adds, by listening to system broadcasts, any app on Android devices can get the information "thus bypassing any permission checks and existing mitigations."

Advertisement

Meanwhile, the report claims that Google has fixed the security flaw with Android 9.0 Pie. Unfortunately, the availability of the final build is currently limited to only Google's Pixel range of smartphones and tablets, and the Essential Phone. A recent report revealed that the share of Android smartphones running Android Pie was less than 0.1 percent in August. The Nightwatch Cybersecurity report says that Google is not planning on fixing this flaw on older versions of the OS.

It is also worth mentioning that not only smartphones with older Android versions are vulnerable to this flaw, but also devices running a forked version of Android are also vulnerable. Devices such as Amazon Fire Phone and Fire Tablets run forked versions of Android.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google, Android
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  2. Best Mobiles Under Rs. 30,000 in India
  3. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  4. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  5. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  6. Google AI Pro Subscribers Now Get 5TB of Storage Across Drive, Photos
  1. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  2. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  3. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  4. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  5. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  6. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  7. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
  8. DoT Reportedly Extends SIM Binding Mandate Till the End of 2026
  9. Government Migrates 16.68 Lakh Official Email Accounts to Zoho Cloud, Spends Rs. 180 Crore
  10. Infinix Note 60 Pro India Launch Date Revealed; Company Teases Active Matrix Feature on Rear Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.