HomeSecurityAndroid apps vulnerable to Dirty Stream vulnerability

Android apps vulnerable to Dirty Stream vulnerability

Many popular Android found on the Google Play Store are susceptible to a specific vulnerability, known as the Dirty Stream attack.

android vulnerability

This path traversal vulnerability could be exploited by a malicious application to replace arbitrary files in the home directory of the affected application.

"The implications of this vulnerability include arbitrary code execution and certificate theft, depending on how the application is used," according to Dimitrios Valsamaras of the Microsoft Threat Intelligence team, in a report published Wednesday.

Read also: Check out the new look of the Google Play Store!

Successful exploitation could allow a hacker to fully control the behavior of the application, as well as use the stolen tokens to gain unauthorized access to the victim's online accounts and related data.

Two of the applications found to be vulnerable to the problem are the following –

Xiaomi File Manager (com.mi. Android.globalFileexplorer) – Over 1 billion installations

WPS Office (cn.wps.moffice_eng) – Over 500 million installations

Android uses the isolation strategy, giving each application its own dedicated data and memory space. To facilitate secure sharing of data and files between applications, it offers a solution called a content provider. However, weaknesses in application implementation can allow access restrictions to an application's private data directory to be bypassed.

“This content-focused model features a defined file sharing mechanism, allowing applications to share their own files with other applications securely and with granular control,” said Dimitris Valsamaras.

However, we often encounter situations where the application receiving data does not check the validity of the contents of the file it receives. It is also critical to use the filename, as provided by the serving application, to temporarily store the incoming file in the internal data directory of the consuming application.

This trap has the potential to cause serious consequences, particularly when an application intended to serve users announces a malicious version of the FileProvider class. The purpose of this action is to allow file sharing between different applications, resulting in the replacement of critical files within the private data space of the served application by the consuming application.

In other words, the mechanism exploits the consumer application's uncritical trust in input data, allowing the sending of arbitrary and potentially malicious payloads via a specially crafted file, with a customized and specific intent, without the user's knowledge or consent, causing code execution.

As a result, this process could allow a hacker to copy the targeted application's preferences file to interface it with a server controlled by them in order to extract sensitive data.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A different scenario involves applications that load native libraries from their own data folder (instead of “/data/app-lib”), allowing a malicious application to exploit this vulnerability. In this way, it can replace a native library with malicious code, which will be executed when the library is loaded.

After conscientiously announcing the problem, both Xiaomi and WPS Office have been patching since February 2024. However, Microsoft argued that the issue could have more widespread implications, highlighting the need for developers to check their apps for potential similar issues.

Google also published its own guidance on the matter, urging developers to properly handle the filename provided by the server application.

android vulnerability

See more: Google passkeys have already been used more than 1 billion times

“When a client application saves a downloaded file, it should ignore the filename provided by the application . Instead, it should use an internally generated unique identifier for the filename,” Google said. “In cases where generating a unique filename is not feasible, the client application should implement procedures to sanitize the provided filename.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS