Google patches Android flaw that allows phishing apps to spoof genuine ones

Advertisement
By NDTV Correspondent | Updated: 16 April 2014 14:17 IST
Google has released a patch that fixes a security vulnerability in Android related to app permissions. Security firm FireEye discovered late last year that apps could modify the icons of other apps on Android home screens and make them point to any other app or website, which would allow attackers to divert users to fake versions of trusted apps and websites in order to steal information.

The security lapse is possible because until now, apps have been able to modify the Android launcher's Read and Write attributes without explicitly asking for user permission. These permissions had previously been classified as "normal", indicating there was no known potential for abuse. "Normal" permissions are not displayed to the user prior to app installation, unlike more sensitive ones such as allowing access to location data, contacts, and the camera.

However, attackers could easily modify icons to point to malicious websites or apps that spoof the interfaces of known, trusted ones, such as banking and shopping apps. Commonly known as phishing, this kind of malware tricks users into entering their PIN numbers, passwords or credit card information, which are then stolen.

The problem affects devices up to and including those running Android 4.4.2, the most recent version. Custom Android skins including those of Samsung and HTC, as well as the aftermarket CyanogenMod, were found to be vulnerable.

FireEye demonstrated a proof of concept app which made it past Google's security scans and was briefly live in the Google Play store, but was withdrawn before anyone could accidentally download it. No requests for permissions were displayed to test users on a Nexus 7 tablet.

Google has now acknowledged the problem and has released a patch to Android device manufacturers, but it will be up to them to decide which devices will receive updates, and when. Android fragmentation is a known problem, and many devices might never be updated. Users must therefore be constantly vigilant of potential phishing attacks.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a Series Tipped to Launch Globally on This Date
  2. How to Reset Your Instagram Reels Algorithm
  3. Google Might Be Making It Hassle-Free to Switch From ChatGPT to Gemini
  4. OpenAI Introduces Codex App With Agentic Coding for macOS
  5. Infinix Note 60, Note 60 Pro, Note 60 Ultra May Be Sold in These Variants
  6. Oppo Find X10 Pro Tipped to Arrive With This Camera Upgrade
  7. Oakley Meta Glasses Now Available in India for Athletes
  8. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra
  9. iQOO 15R Battery Capacity, Thickness Announced by Company
  10. Vivo X200T Is Now Available for Purchase in India: See Price, Offers
  1. NASA’s Perseverance Makes History on Mars with Claude AI at the Helm
  2. Mozilla Firefox Will Let You Decide How Much AI You Want in Your Browser
  3. Oppo Find X10 Pro Will Launch With Two 200-Megapixel Rear Cameras, Tipster Claims
  4. Psych Siddhartha OTT Release Date: When and Where to Watch it Online?
  5. Parasakthi OTT Release Revealed: When and Where to Watch Sivakarthikeyan Starrer Movie Online?
  6. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra: Expected Specifications, Features
  7. Sampradayini Suppini Suddapoosani Now Streaming Online: What You Need to Know
  8. Lucky The Superstar OTT Release Date Revealed: Know When and Where to Watch This Upcoming Tamil Comedy Drama Film
  9. Redmi K Pad 2 Tipped to Launch With MediaTek Dimensity 9500 SoC, Bose-Tuned Speakers
  10. Nioh 3 Will Be a PS5 Console Exclusive for 6 Months, Could Launch on Other Platforms Later This Year
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.