Security researchers are warning of SSL vulnerabilities in Android applications, which could allow man- in- the -middle attacks and the monitoring of communications between clients and application servers.
After analyzing the 1,000 most popular free apps on Google Play, FireEye security researchers found that 674 of them contain vulnerabilities related to the implementation/verification of SSL connections, which could be exploited by attackers to intercept sensitive information.
This could be achieved with the help of man-in-the-middle attacks, which aim to monitor traffic and data exchanged between Android devices and application servers.
The FireEye Mobile Security Team discovered that nearly 73% of 614 applications that rely on SSL/TLS protocols to communicate with servers have trust managers that do not perform certificatevalidation.
Additionally, 77% of the 285 applications using Webkit ignore SSL errors generated in Webkit.
FireEye notified the application developers about the vulnerabilities, and they committed to patching them in future versions of their applications.
For more information about the vulnerabilities, you can visit the FireEye.

