HomeSecurityUC Browser feature allows hackers to break into Android phones...

UC Browser feature lets hackers hack Android phones remotely

Warning! If you use UC Browser on your smartphones, you should uninstall it immediately. Why? Because the Chinese-made UC Browser contains a “questionable” feature that could be exploited by remote attackers to automatically download and execute code on Android.

UC

Developed by Alibaba-owned UCWeb, UC Browser is one of the most popular mobile browsers, especially in China and India, with a huge user base of over 500 million users worldwide.

According to a new report published today by the company Dr. Web, since at least 2016, UC Browser for Android has had a “hidden” feature that allows the company to download new libraries and modules from its servers at any time and install them on users' mobile devices.

What's worrying? It turns out that the aforementioned feature downloads new plugins from the company's server via insecure HTTP protocol instead of encrypted HTTPS protocol, thus allowing attackers to perform "man-in-the-middle" (MiTM) attacks and "push" malicious modules to targeted devices.

"Since UC Browser runs on unsigned plug-ins, it launches malicious modules without any verification," the researchers say.

In a PoC video published by Dr. Web, researchers demonstrated how they were able to replace a plugin for viewing PDF documents with malicious code using a MiTM attack, forcing UC Browser to compose a new text message instead of opening the file.

"Thus, MITM attacks can help cybercriminals use UC Browser to spread malicious plugins that perform a wide variety of actions," the researchers explain.

"For example, they can display phishing emails to steal usernames, passwords, bank card details and other personal data. In addition, the trojan will access protected browser files and steal passwords stored in the program directory.".

UC Browser violates Google Play Store Policies

Since the feature allows UCWeb to download and execute arbitrary code on users' devices, without reinstalling a full new version of the UC Browser app, it also violates Play Storeby bypassing Google's servers.

“This violates Google’s rules for software distributed in its app store. Current policy states that apps downloaded from Google Play cannot change their own code or download software components from third-party sources,” the researchers say.

"These rules were implemented to prevent the distribution of trojans that download and launch malicious plugins.".

This dangerous feature has been found in both UC Browser and UC Browser Mini, with all relevant versions including the most recent version of the browsers released to date.

Dr. Web responsibly reported its findings to the developer of both UC Browser and UC Browser Mini, but they refused to even comment on the matter. It then reported the issue to Google.

Currently, UC Browser and UC Browser Mini are "still available and can download new add-ons by bypassing Google Play servers," the researchers say.

Such a feature can be used in supply chain attack scenarios, allowing attackers to push malicious updates to a large number of users at once – just as we recently saw in the ASUS supply chain attack that affected over 1 million computers.

So, users have only one option… get rid of the browser until the company fixes the problem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS