A Spanish security researcher, Pau Oliva Fora, has released a “quick” proof-of-concept exploit for an Android that could be exploited to turn any app into a Trojan without breaking its encrypted signature.
The expert emphasizes that the details of the bug had already been made public by CyanogenMod and that he simply wrote a POC based on the available information.
[tweet_embed id=354156596638650368]
CyanogenMod has already addressed the issue, which is said to affect around 900 million Android devices. Google has said it has already patched the vulnerability.
According to Security Ledger, some mobile manufacturers, such as Samsung, have started working on a patch.
So far, there is no evidence that cybercriminals are exploiting the flaw. However, the main concern is that it usually takes too long for device manufacturers to release security updates to protect their customers.

