Google patches Android flaw that allows phishing apps to spoof genuine ones

Advertisement
By NDTV Correspondent | Updated: 16 April 2014 14:17 IST
Google has released a patch that fixes a security vulnerability in Android related to app permissions. Security firm FireEye discovered late last year that apps could modify the icons of other apps on Android home screens and make them point to any other app or website, which would allow attackers to divert users to fake versions of trusted apps and websites in order to steal information.

The security lapse is possible because until now, apps have been able to modify the Android launcher's Read and Write attributes without explicitly asking for user permission. These permissions had previously been classified as "normal", indicating there was no known potential for abuse. "Normal" permissions are not displayed to the user prior to app installation, unlike more sensitive ones such as allowing access to location data, contacts, and the camera.

However, attackers could easily modify icons to point to malicious websites or apps that spoof the interfaces of known, trusted ones, such as banking and shopping apps. Commonly known as phishing, this kind of malware tricks users into entering their PIN numbers, passwords or credit card information, which are then stolen.

The problem affects devices up to and including those running Android 4.4.2, the most recent version. Custom Android skins including those of Samsung and HTC, as well as the aftermarket CyanogenMod, were found to be vulnerable.

FireEye demonstrated a proof of concept app which made it past Google's security scans and was briefly live in the Google Play store, but was withdrawn before anyone could accidentally download it. No requests for permissions were displayed to test users on a Nexus 7 tablet.

Google has now acknowledged the problem and has released a patch to Android device manufacturers, but it will be up to them to decide which devices will receive updates, and when. Android fragmentation is a known problem, and many devices might never be updated. Users must therefore be constantly vigilant of potential phishing attacks.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  2. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  3. These Three Pro Models Could Launch as Part of the Motorola Edge 70 Series
  4. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  5. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  6. Google Pixel 11 Pro XL CAD Renders Leak Online
  7. Meta Reportedly Warns WhatsApp Users About This Fake App Spying on Them
  8. Best Mobiles Under Rs. 30,000 in India
  9. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  10. Redmi Note 15 SE 5G Debuts in India With a Vegan Leather Finish: See Price
  1. OpenAI Brings ChatGPT to Apple CarPlay, but It Cannot Access Navigation and Live Location Data
  2. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale; iPad, Watch Available With Offers
  3. Google Pixel 11 Pro XL Leaked CAD Renders Reveal Design Identical to Pixel 10 Pro XL
  4. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  5. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  6. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  7. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  8. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  9. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  10. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.