A team of IBM security researchers discovered a major security flaw in Android 9 months ago , which allows hackers to obtain transaction security keys .
These important keyscan be used for secure transactions from banking apps, passwords for VPNs, and the PIN or combination for unlocking the device.
The vulnerabilityis located in the secure key and ID storage service, Android KeyStore, and is caused by a possible buffer overflow.
It may be difficult for a third party to gain access to these keys, but it is still a critical security vulnerability that affects a large percentage of mobile devices.
Google has already fixed the problem, but it has only been fixed on devices running Android 4.4 .
According to the usage rate of Android versions for the last month, 86.4% of devices with operating system version 4.3 and below remain vulnerable.
Source: e-pcmag.gr

