Android users are notified by security experts when they discover a problem in a widely used Google app .
Android is one of the most used operating systems in the world, with more than two billion active devices running Google's mobile operating system every month.
The extremely popular operating system comes with many pre-installed Google apps, which users can use as soon as they turn on their device.
Google Chrome is the default browser on Android devices.
And experts at Nightwatch Cybersecurity discovered a vulnerability in the Android version of Chrome that could leak details about the device.
Information about the hardware model, firmware version, and security level of the device could be leaked.
In a post, Nightwatch researcher Yakov Shafranovich said: “Google’s Chrome browser, WebView, and Chrome Tab for Android reveal information about the hardware model, firmware version, and security update of the device it is running on.
“This also affects any Android apps that use Chrome to render web content.
“This information can be used to identify users and unlock fingerprint devices.”
Shafranovich warned: “It can also be used to determine which vulnerabilities of a particular device are vulnerable to exploit.”.
The researcher also said that the problem was discovered in 2015.
Shafranovich said: “While Google dismissed the initial bug report in 2015, it had issued a partial fix in October 2018 for Chrome v70.
“The fix hides the firmware information while preserving the hardware model identifier.
“All previous versions are believed to be affected. Users are encouraged to upgrade to version 70 or later.
“Since this fix does not apply to WebView usage, application developers will need to manually override the User Agent configuration in their applications.”
In other Android news, Express.co.uk recently reported on fake apps discovered on the Google Play Store.
Quick Heal security experts have identified the compromised applications, which have been downloaded tens of thousands of times.
These apps were found in the Google Play Store and disguised as PDF readers, scanners, and converters.
However, while the apps appear to be genuine, Quick Heal said they do not offer the functionality that users download them for.
Instead, these apps are designed to increase the number of downloads of other apps and improve their ratings.
In an online post, Quick Heal stated: “Quick Heal Security Lab has identified a few FakeApps with more than 50,000 installs on the Google Play Store.
“These apps look genuine as PDF reader, PDF Downloader, PDF Scanner, etc., but they have no such functionality.
“The main purpose of these apps is to increase the number of downloads of other apps and improve their ratings.”.
Quick Heal reported these apps to Google and they have since been removed from the Google Play Store.
