Google patches Android flaw that allows phishing apps to spoof genuine ones

Advertisement
By NDTV Correspondent | Updated: 16 April 2014 14:17 IST
Google has released a patch that fixes a security vulnerability in Android related to app permissions. Security firm FireEye discovered late last year that apps could modify the icons of other apps on Android home screens and make them point to any other app or website, which would allow attackers to divert users to fake versions of trusted apps and websites in order to steal information.

The security lapse is possible because until now, apps have been able to modify the Android launcher's Read and Write attributes without explicitly asking for user permission. These permissions had previously been classified as "normal", indicating there was no known potential for abuse. "Normal" permissions are not displayed to the user prior to app installation, unlike more sensitive ones such as allowing access to location data, contacts, and the camera.

However, attackers could easily modify icons to point to malicious websites or apps that spoof the interfaces of known, trusted ones, such as banking and shopping apps. Commonly known as phishing, this kind of malware tricks users into entering their PIN numbers, passwords or credit card information, which are then stolen.

The problem affects devices up to and including those running Android 4.4.2, the most recent version. Custom Android skins including those of Samsung and HTC, as well as the aftermarket CyanogenMod, were found to be vulnerable.

FireEye demonstrated a proof of concept app which made it past Google's security scans and was briefly live in the Google Play store, but was withdrawn before anyone could accidentally download it. No requests for permissions were displayed to test users on a Nexus 7 tablet.

Google has now acknowledged the problem and has released a patch to Android device manufacturers, but it will be up to them to decide which devices will receive updates, and when. Android fragmentation is a known problem, and many devices might never be updated. Users must therefore be constantly vigilant of potential phishing attacks.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  4. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. Nothing Phone 3a Lite Goes on Sale in India at This Price
  7. Airtel Discontinues These Prepaid Recharge Packs in India
  8. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  9. Realme Says It Will Launch Two New Narzo Smartphones in India Soon
  10. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  1. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  2. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  3. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  4. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  5. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  6. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  7. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  8. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  9. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  10. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.