mercredi 11 février 2015

Play Store vulnerability allows hackers to install apps without consent topic






A new security vulnerability affecting android users as an X-Frame-Options flaw which when combined with a recent Android WebView (Jelly Bean) bug allows hackers to install apps on users device without their permission. The vulnerability affects users running Android 4.3 Jelly Bean and that use a UXSS vulnerable browser. As Tod Beardsley, engineering manager at Rapid7 reports:


Quote:









"Users of these platforms may also have installed vulnerable aftermarket browsers. Until the Google Play store XFO [X-Frame-Options] gap is mitigated, users of these web applications who habitually sign in to their Google Account will remain vulnerable."




Source

How to prevent being vulnerable
  1. Update to newer Android version

  2. Use a browser like Chrome or firefox that isn't vulnerable to UXSS

  3. Don't keep your Play Store account logged into any third party browser apps

Source






Aucun commentaire:

Enregistrer un commentaire