MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
android
Search

Samsung's Android App-Signing Key Has Leaked, is Being Used To Sign Malware

Thursday December 8, 2022. 09:40 PM , from Slashdot
Lukasz Siewierski, a member of Google's Android Security Team, has a post on the Android Partner Vulnerability Initiative (AVPI) issue tracker detailing leaked platform certificate keys that are actively being used to sign malware. From a report: The post is just a list of the keys, but running each one through APKMirror or Google's VirusTotal site will put names to some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets. Esper Senior Technical Editor Mishaal Rahman, as always, has been posting great info about this on Twitter. As he explains, having an app grab the same UID as the Android system isn't quite root access, but it's close and allows an app to break out of whatever limited sandboxing exists for system apps. These apps can directly communicate with (or, in the case of malware, spy on) other apps across your phone. Imagine a more evil version of Google Play Services, and you get the idea.

Read more of this story at Slashdot.
https://it.slashdot.org/story/22/12/08/1440250/samsungs-android-app-signing-key-has-leaked-is-being-...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Fri 26 - 17:04 CEST