Many popular Android found on the Google Play Store are susceptible to a specific vulnerability, known as the Dirty Stream attack.

This path traversal vulnerability could be exploited by a malicious application to replace arbitrary files in the home directory of the affected application.
"The implications of this vulnerability include arbitrary code execution and certificate theft, depending on how the application is used," according to Dimitrios Valsamaras of the Microsoft Threat Intelligence team, in a report published Wednesday.
Read also: Check out the new look of the Google Play Store!
Successful exploitation could allow a hacker to fully control the behavior of the application, as well as use the stolen tokens to gain unauthorized access to the victim's online accounts and related data.
Two of the applications found to be vulnerable to the problem are the following –
Xiaomi File Manager (com.mi. Android.globalFileexplorer) – Over 1 billion installations
WPS Office (cn.wps.moffice_eng) – Over 500 million installations
Android uses the isolation strategy, giving each application its own dedicated data and memory space. To facilitate secure sharing of data and files between applications, it offers a solution called a content provider. However, weaknesses in application implementation can allow access restrictions to an application's private data directory to be bypassed.
“This content-focused model features a defined file sharing mechanism, allowing applications to share their own files with other applications securely and with granular control,” said Dimitris Valsamaras.
However, we often encounter situations where the application receiving data does not check the validity of the contents of the file it receives. It is also critical to use the filename, as provided by the serving application, to temporarily store the incoming file in the internal data directory of the consuming application.
This trap has the potential to cause serious consequences, particularly when an application intended to serve users announces a malicious version of the FileProvider class. The purpose of this action is to allow file sharing between different applications, resulting in the replacement of critical files within the private data space of the served application by the consuming application.
In other words, the mechanism exploits the consumer application's uncritical trust in input data, allowing the sending of arbitrary and potentially malicious payloads via a specially crafted file, with a customized and specific intent, without the user's knowledge or consent, causing code execution.
As a result, this process could allow a hacker to copy the targeted application's preferences file to interface it with a server controlled by them in order to extract sensitive data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A different scenario involves applications that load native libraries from their own data folder (instead of “/data/app-lib”), allowing a malicious application to exploit this vulnerability. In this way, it can replace a native library with malicious code, which will be executed when the library is loaded.
After conscientiously announcing the problem, both Xiaomi and WPS Office have been patching since February 2024. However, Microsoft argued that the issue could have more widespread implications, highlighting the need for developers to check their apps for potential similar issues.
Google also published its own guidance on the matter, urging developers to properly handle the filename provided by the server application.

See more: Google passkeys have already been used more than 1 billion times
“When a client application saves a downloaded file, it should ignore the filename provided by the application . Instead, it should use an internally generated unique identifier for the filename,” Google said. “In cases where generating a unique filename is not feasible, the client application should implement procedures to sanitize the provided filename.”
Source: thehackernews
