HomeSecurityAndroid: Bug in NFC beaming allows hackers to "plant" malware

Android: NFC beaming bug allows hackers to plant malware

Google last month fixed a bug in Android that allowed hackers to transmit malware to a nearby phone through a little-known feature of the Android OS called NFC beaming .

NFC beaming works through an internal service of the Android OS known as Android Beam. This service allows an Android device to send data such as images, files, videos, or even apps to another nearby device using NFC (Near-Field Communication) wireless channels, as an alternative to WiFi or Bluetooth.

NFC beaming

Typically, applications (APK files) sent via NFC beaming are saved to disk and a notification appears on the screen. The notification asks the device owner if they want to allow the NFC service to install an application from an unknown source.

However, in January of this year, security researcher Y. Shafranovich discovered that apps sent via NFC beaming on Android 8 (Oreo) or later do not display the approval prompt in the notification. Instead, the notification allows the user to install the app with one tap, without any security warning.

The lack of a security warning is a major issue for Android. Android devices are not allowed to install apps from “unknown sources” – as anything installed outside of the official Play Store is considered untrustworthy and unverified.

If users wish to install an app outside of the Play Store, they must visit the “Install apps from unknown sources” section of the Android OS and enable the feature.

Until Android 8, this “Install from unknown sources” option was a system-wide setting, the same for all apps. But starting with Android 8, Google redesigned this mechanism into an app-based setting.

In modern Android versions, users can visit the “Install unknown apps” section in Android’s security settings and allow specific apps to install other apps.

Android

The CVE-2019-2114 bug occurred because the Android Beam app had been whitelisted, receiving the same level of trust as the official app on the Play Store.

Google said there was no need for concern, as the Android Beam service was not created for installing apps, but simply as a way to transfer data from device to device.

The October 2019 Android patches remove the Android Beam service from the OS whitelist.

However, many millions of users remain at risk. If users have NFC and Android Beam enabled, a hacker could plant malware (malicious apps) on their phones.

Since there is no security warning about installing from an unknown source, tapping the notification starts the installation of the malicious apps. There is a risk that many users will misinterpret the message as coming from the Play Store and install the app, thinking it is an update.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS