Google patches Android flaw that allows phishing apps to spoof genuine ones

Advertisement
By NDTV Correspondent | Updated: 16 April 2014 14:17 IST
Google has released a patch that fixes a security vulnerability in Android related to app permissions. Security firm FireEye discovered late last year that apps could modify the icons of other apps on Android home screens and make them point to any other app or website, which would allow attackers to divert users to fake versions of trusted apps and websites in order to steal information.

The security lapse is possible because until now, apps have been able to modify the Android launcher's Read and Write attributes without explicitly asking for user permission. These permissions had previously been classified as "normal", indicating there was no known potential for abuse. "Normal" permissions are not displayed to the user prior to app installation, unlike more sensitive ones such as allowing access to location data, contacts, and the camera.

However, attackers could easily modify icons to point to malicious websites or apps that spoof the interfaces of known, trusted ones, such as banking and shopping apps. Commonly known as phishing, this kind of malware tricks users into entering their PIN numbers, passwords or credit card information, which are then stolen.

The problem affects devices up to and including those running Android 4.4.2, the most recent version. Custom Android skins including those of Samsung and HTC, as well as the aftermarket CyanogenMod, were found to be vulnerable.

FireEye demonstrated a proof of concept app which made it past Google's security scans and was briefly live in the Google Play store, but was withdrawn before anyone could accidentally download it. No requests for permissions were displayed to test users on a Nexus 7 tablet.

Google has now acknowledged the problem and has released a patch to Android device manufacturers, but it will be up to them to decide which devices will receive updates, and when. Android fragmentation is a known problem, and many devices might never be updated. Users must therefore be constantly vigilant of potential phishing attacks.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. PS Plus Prices Hiked Across All Tiers in India: Check New Pricing
  2. Xiaomi 17 Max Debuts With 8,000mAh Battery, Leica-Tuned Cameras: See Price
  3. Maa Behen OTT Release: When and Where to Watch it Online?
  4. HMD Vibe 2 5G Launched in India With 6,000mAh Battery
  5. Oppo Find X10 Series Tipped to Launch With Notable Battery Upgrades
  6. Oppo Find X9 Ultra Launches in India With Hasselblad-Tuned Camera Setup
  7. Xiaomi Clip Open-Ear Earbuds Launched With Up to 38 Hours Total Battery Life
  8. Oppo Enco Air 5 Pro With 12mm Drivers Arrives in India at This Price
  9. Oppo Reno 16 Series Camera Details Teased, Might Launch in India Soon
  1. Samsung Preparing to Launch Galaxy Buds Able as Clip-On Open-Ear Earbuds: Report
  2. Redmi Note 17 Reportedly Spotted on GSMA Database; May Launch Earlier Than Expected
  3. Oppo Reno 16 Chipset Details Surface via Geekbench Listing; May Feature Dimensity 8500 Chip, 12GB RAM
  4. Scientists Discover New Fuel-Saving Route to the Moon
  5. Madhu Vidhu OTT Release: Where to Watch, Plot, Cast, IMDb Rating, and More
  6. Maa Behen OTT Release Revealed: When and Where to Watch it Online?
  7. LOL: Last One Laughing Germany Season 7 Out on OTT: Know Where to Watch it Online
  8. Warrant: From the World of Vilangu OTT Release Date: When and Where to Watch it Online?
  9. Xiaomi Clip Open-Ear Earbuds Launched With LHDC 5.0 Audio, Up to 38 Hours Total Battery Life: Price, Specifications
  10. Sathi Leelavathi Now Streaming on SunNXT: Everything You Need to Know About Plot, Cast, and More
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.