HomeSecurityGoogle fixes Fake ID security flaw in Android

Google fixes Fake ID security flaw in Android

Android Fake IDBluebox Security, a mobile security company, has discovered a very serious security flaw in Android. The vulnerability has existed since Android 2.1. This Fake ID vulnerability can be used by malware to impersonate secure applications without any notification to the user.

This allows the malware to act as if it has full authorization from the owner, just like high-level security programs. Bluebox claims that with Fake ID “safe applications are used by malware to escape the sandbox and perform one or more malicious actions. For example, introducing a Trojan horse into an Adobe Systems impersonation application, or granting access to NFC [Neat Field Communication], payments from Google Wallet. The malicious application, disguised as 3LM, could take control of the entire device management.” Ironically, 3LM is part of an Android system for enterprise security.

Bluebox is not exaggerating. This particular security flaw is very important and exists in all versions of Android from 2.1 onwards up to the latest version KitKat.

The good news: Google has patched the vulnerability.
A Google spokesperson said:
“We appreciate Bluebox for responsibly reporting this vulnerability to us. Third-party research is one way to make Android stronger. After this vulnerability was disclosed, we quickly issued a patch that was distributed by our partners and the AOSP [Android Open Source Project]. Google Play and App Verification have also been strengthened with protections for this issue. At this time, we have scanned all apps on Google Play, as well as those that Google has recently reviewed, and we have not seen any evidence of any attempts to exploit this vulnerability.”

So, for now, you're probably safe. To make sure you stay safe, follow these basic steps for Android security.

  • Do not visit or download files from suspicious websites. Porn websites are particularly dangerous.
    Do not download programs from third parties.
  • Look carefully at any program before installing it to make sure it is legitimate and only asks for necessary permissions.
  • Upgrade, if possible, to the latest version of Android.
  • Use a high-quality anti-virus.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS