A new Android design flaw discovered by Bluebox Security allows malicious apps to gain extensive control over a user's device without asking for special permissions during installation. The flaw affects nearly all Android phones sold since 2010.
Bluebox has dubbed the bug “Fake ID” because it allows malicious apps to pass fake certificates to Android, which is unable to verify the app’s cryptographic signature. Instead, Android grants the fake app all the same access rights as the legitimate one.
📧
Subscribe to the SecNews Newsletter

