146 security flaws uncovered in pre-installed Android apps

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=8GK9RiyKRXU



Duration: 2:58
21 views
0


Reported today on TheNextWeb

For the full article visit: http://bit.ly/2qe4tXe

146 security flaws uncovered in pre-installed Android apps

Unless you’re purchasing a Pixel phone — which promises a stock user experience — pre-installed apps from Android handset manufacturers are a given. Turns out, they’re not only bloatware, but are also full of security flaws.

Researchers at Kryptowire have uncovered 146 security vulnerabilities in pre-installed apps across 29 Android OEMs (aka original equipment manufacturers), underscoring the vast scope of the problem.

Let’s go bowling

Join us on Dec. 11 for the ultimate team outing

YES

The shortcomings discovered in the study — funded by the Department of Homeland Security — range from unauthorized app installs to the ability to modify system and wireless settings, and even record audio.

More troubling, it includes apps from some well-known OEMs like Asus, Samsung, and Xiaomi.

Samsung disputed the findings in a statement to Wired, stating “we have promptly investigated the apps in question and have determined that appropriate protections are already in place.”

Since last year, Google has leveraged a system called Build Test Suite (BTS) to scan for potentially harmful pre-installed apps across custom Android builds for devices that ship with its services.

As the company explains in its “Android Security 2018 Year in Review” report released earlier this March:

OEMs submit their new or updated build images to BTS. BTS then runs a series of tests that look for security issues on the system image. One of these security tests scans for pre-installed PHAs included in the system image. If we find a PHA on the build, we work with the OEM partner to remediate and remove the PHA from the build before it can be offered to users.

But despite these security checks in place, malicious apps continue to slip through the cracks, as evidenced by Kryptowire’s research.

What makes the situation more insidious is the fact that these are OEM apps. When third-party apps downloaded by users are found to contain malware, there’s at least a choice to uninstall them. With pre-installed apps, on the other hand, there is no option to get rid of the offended functionality.

Worse, there’s no guarantee that OEMs will even issue a patch for older devices.

Google, for its part, has been actively tring to weed out harmful apps from the platform. It recently partnered with ESET, Lookout, and Zimperium to identify shady third-party apps before they end up on users’ devices.

Perhaps it’s time to apply the same stingent checks for OEM-made apps too.




Other Videos By Colin Boyd SEO


2019-11-18Ohi raises $2.75M to power same-day delivery for brands that aren’t Amazon
2019-11-18The Mustang Mach-E is the exciting shape of the electric future
2019-11-18Consumer Reports says Samsung's Galaxy Buds beat Apple's AirPods Pro in sound quality test
2019-11-18Samsung has multiple new camera modes in the works for future phones, code suggests
2019-11-18John Legere is stepping down as CEO of T-Mobile, succeeded by deputy Mike Sievert on May 1
2019-11-18John Legere will step down as T-Mobile CEO next year
2019-11-18Cybersecurity firm Sonatype acquired by Vista Equity
2019-11-18Intel reveals Ponte Vecchio, its Xe HPC GPU
2019-11-18Logitech’s Adaptive Gaming Kit is a cheaper way in to accessible gaming
2019-11-18The product manager secrets to surviving the 3 pivotal startup phases
2019-11-18146 security flaws uncovered in pre-installed Android apps
2019-11-18Heetch adds $4 million to its Series B round
2019-11-18MMC Ventures outs new £100M ‘Scale Up’ fund to double-down on its portfolio at the later-stage
2019-11-17Yahoo Japan and Line Corp confirm merger agreement
2019-11-17Nintendo is adding paid memberships to Animal Crossing: Pocket Camp
2019-11-17Ford unveils the Mustang Mach-E, an all-electric crossover with muscle car roots
2019-11-17Every angle of Ford’s all-electric Mustang Mach-E
2019-11-17Google Stadia nearly doubles launch lineup to 22 games on eve of debut
2019-11-17Original Content podcast: Disney’s ‘Mandalorian’ is never boring
2019-11-17Max Q: SpaceX starts building out its production Starlink constellation
2019-11-17Bill V Bowie: How (not) to sell a tech idea