Researchers have discovered that more than 500 million users Android are at risk of Man-in-the-Middle attacks, due to the UC Browser app.
UC Browser is the most popular browser on the platform . Today, it has over 500 million users.
Over time, many suspicious activities and vulnerabilities related to UC Browser have been identified. These issues need to be addressed immediately, otherwise all users will be at risk.
Recently, researchers discovered that apps UC Browser Mini made a request over an unprotected channel (HTTP) and downloaded an additional Android Package Kit (APK) from a remote server.
Researchers discovered 3 unusual activities in the UC Browser app:
- Downloading an APK from third parties (which violates Google Play policy)
- Use of an insecure channel (which allows man-in-the-middle attacks)
- Installation of the APK to external storage (/storage/emulated/0) (which allows other apps, with appropriate permissions, to tamper with the APK)
Downloading APK from third parties
According to the researchers, the app sends multiple requests and installs an APK on the user's device. Specifically, it installs it on an external storage. However, there is no trace of the installation process.
As we said above, downloading an APK from a third party is against Google Play policy.
“An app distributed through Google Play may not be modified, replaced, or updated by any method other than the Google Play update mechanism. Similarly, an app may not download executable code (e.g. dex, JAR, .so files) from any source other than Google Play.”
Insecure channels
UC browsers download the APK from unencrypted channels, which can allow a man-in-the-middle attack.
In March, researchers had discovered a similar security issue, which allowed hackers to download and execute code on Android devices and carry out man-in-the-middle attacks.
Researchers believe that “Perhaps the same app was re‑uploaded to Google Play under a different name and developer with modified code for downloading additional APKs”.

Installation of APK on external storage
“The APK that is placed in external storage or any other app with storage permission (android: name = android.permission.READ / WRITE_EXTERNAL_STORAGE) can access this location and can compromise the APK.”.
There is no trace of installation. So, the researchers installed the additional APK and found that it came from another app store called “9 Apps.”
The app store also offered many applications for adults.
Google has been notified of the issue and recommends that all users update their UC Browser and UC Mini apps to the latest version.
