Google patches Android flaw that allows phishing apps to spoof genuine ones

Advertisement
By NDTV Correspondent | Updated: 16 April 2014 14:17 IST
Google has released a patch that fixes a security vulnerability in Android related to app permissions. Security firm FireEye discovered late last year that apps could modify the icons of other apps on Android home screens and make them point to any other app or website, which would allow attackers to divert users to fake versions of trusted apps and websites in order to steal information.

The security lapse is possible because until now, apps have been able to modify the Android launcher's Read and Write attributes without explicitly asking for user permission. These permissions had previously been classified as "normal", indicating there was no known potential for abuse. "Normal" permissions are not displayed to the user prior to app installation, unlike more sensitive ones such as allowing access to location data, contacts, and the camera.

However, attackers could easily modify icons to point to malicious websites or apps that spoof the interfaces of known, trusted ones, such as banking and shopping apps. Commonly known as phishing, this kind of malware tricks users into entering their PIN numbers, passwords or credit card information, which are then stolen.

The problem affects devices up to and including those running Android 4.4.2, the most recent version. Custom Android skins including those of Samsung and HTC, as well as the aftermarket CyanogenMod, were found to be vulnerable.

FireEye demonstrated a proof of concept app which made it past Google's security scans and was briefly live in the Google Play store, but was withdrawn before anyone could accidentally download it. No requests for permissions were displayed to test users on a Nexus 7 tablet.

Google has now acknowledged the problem and has released a patch to Android device manufacturers, but it will be up to them to decide which devices will receive updates, and when. Android fragmentation is a known problem, and many devices might never be updated. Users must therefore be constantly vigilant of potential phishing attacks.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO 15R Battery Capacity, Thickness Announced by Company
  2. Nothing Phone 4a Series Tipped to Launch Globally on This Date
  3. Mozilla Firefox Will Let You Decide How Much AI You Want in Your Browser
  4. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra
  5. Infinix Note 60, Note 60 Pro, Note 60 Ultra May Be Sold in These Variants
  6. Google Might Be Making It Hassle-Free to Switch From ChatGPT to Gemini
  7. Redmi K Pad 2 Tipped to Feature Bose-Tuned Speakers and This MediaTek Chip
  8. Nintendo Switch Is Now Nintendo's Best-Selling Console Ever
  9. Oakley Meta Glasses Now Available in India for Athletes
  10. Psych Siddhartha OTT Release Date: When and Where to Watch it Online?
  1. Motorola Razr 70 Global Launch Seems Imminent as Foldable Phone Visits UAE’s TDRA Certification Database
  2. Crypto Wrench Attacks Surged in 2025, Total Recorded Losses Hit $41 Million: Report
  3. Philips TAA1009 TWS Earphones, SHP9500 Headphones Launched in India Alongside New Soundbar, Speaker Models
  4. Supreme Court Questions WhatsApp Policy of Sharing User Data With Meta Entities
  5. Nintendo Switch Becomes Best-Selling Nintendo Console Ever; Switch 2 Sales Cross 17 Million Units
  6. NASA’s Perseverance Makes History on Mars with Claude AI at the Helm
  7. Redmi K90 Ultra Tipped to Launch With Dimensity 9500 Chip, Active Cooling Fan
  8. Mozilla Firefox Will Let You Decide How Much AI You Want in Your Browser
  9. Oppo Find X10 Pro Will Launch With Two 200-Megapixel Rear Cameras, Tipster Claims
  10. Psych Siddhartha OTT Release Date: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.