Google patches Android flaw that allows phishing apps to spoof genuine ones

Advertisement
By NDTV Correspondent | Updated: 16 April 2014 14:17 IST
Google has released a patch that fixes a security vulnerability in Android related to app permissions. Security firm FireEye discovered late last year that apps could modify the icons of other apps on Android home screens and make them point to any other app or website, which would allow attackers to divert users to fake versions of trusted apps and websites in order to steal information.

The security lapse is possible because until now, apps have been able to modify the Android launcher's Read and Write attributes without explicitly asking for user permission. These permissions had previously been classified as "normal", indicating there was no known potential for abuse. "Normal" permissions are not displayed to the user prior to app installation, unlike more sensitive ones such as allowing access to location data, contacts, and the camera.

However, attackers could easily modify icons to point to malicious websites or apps that spoof the interfaces of known, trusted ones, such as banking and shopping apps. Commonly known as phishing, this kind of malware tricks users into entering their PIN numbers, passwords or credit card information, which are then stolen.

The problem affects devices up to and including those running Android 4.4.2, the most recent version. Custom Android skins including those of Samsung and HTC, as well as the aftermarket CyanogenMod, were found to be vulnerable.

FireEye demonstrated a proof of concept app which made it past Google's security scans and was briefly live in the Google Play store, but was withdrawn before anyone could accidentally download it. No requests for permissions were displayed to test users on a Nexus 7 tablet.

Google has now acknowledged the problem and has released a patch to Android device manufacturers, but it will be up to them to decide which devices will receive updates, and when. Android fragmentation is a known problem, and many devices might never be updated. Users must therefore be constantly vigilant of potential phishing attacks.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R, OnePlus 15R Ace Edition Launch Today: All You Need to Know
  2. Realme 16 Pro+ 5G Listed on Certification Website With These Specifications
  3. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  4. Dhurandhar OTT Release Date: What We Know So Far
  5. OnePlus 15, Nord CE 5 Prices Slashed During Community Sale: See Offers
  6. GTA 6 Characters Guide: Know Every Character Rockstar Has Teased So Far
  7. Moto G Power (2026) Launched With MediaTek Dimensity 6300 SoC: Details
  8. Google Pay Brings Its First Co-Branded UPI-Powered Digital Credit Card
  9. Motorola Signature Phone Could Launch Soon: See Leaked Design, Colourways
  1. Flex By Google Pay: Google Partners With Axis Bank to Introduce UPI-Powered, Digital Credit Card
  2. Warner Bros. Plans to Reject Paramount Bid on Funding, Terms
  3. Amazon Pay Adds Support for Biometric Authentication for UPI Payments in India
  4. The Pitt Season 2 OTT Release Date Revealed: Know When and Where to Watch it Online
  5. iPhone 18 Pro, iPhone Fold to Feature Relocated Selfie Camera; iPhone 17e to Offer MagSafe Support: Report
  6. Development on The Elder Scrolls 6 Is 'Progressing Really Well', Says Bethesda Director Todd Howard
  7. Meta’s New Open-Source SAM Audio AI Model Can Isolate Sounds From Audio Mixtures
  8. Vivo V70 Stops By US FCC Database; Listing Reveals RAM and Storage Specifications
  9. Taskaree: The Smuggler’s Web OTT Release Date: When and Where to Watch Emraan Hashmi's Intense Crime Thriller
  10. Home Town Streaming Now Online: Know Where to Watch This American Reality Show
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.