Janus Vulnerability: A serious security flaw (CVE-2017-13156) in Android allows attackers to modify the code of various applications without affecting their digital signature. The problem arises because a parameterized .apk file and a .dex file can be valid at the same time.
The Janus vulnerability, as it was named by the researchers at Guard Square, has the ability to add additional bytes of information to the file types mentioned above. A .dex file, which is quite similar to a Windows .zip file, is compressed data. On Android, if we click on such a file, it will install the application it contains. A .dex file contains a part of the data that has to do with the structure of the corresponding application (.apk) that we installed. When we click to open an application, we activate a function that immediately searches first in .dex to find the structure of the application and then searches in .apk to activate the other services it can provide us, resulting in our applications starting faster.
The problem lies in the operation between these two. Someone who exploits this vulnerability can essentially infect a .dex file inside an .apk with malicious code without affecting its authenticity signature. So, if someone upgrades an application and the .dex data is read first, the infected code will pass along.
The versions affected by Janus are Android 5.0 and later. However, devices with an Android security patch level dated November 2017 (and later) are protected as the vulnerability has been patched.

