Half of all devices running Androidare vulnerable to a recently discovered vulnerability that could allow someone to secretly modify or replace legitimate, clean apps with malicious ones that steal passwords and other sensitive data.
The “Android installer hijacking ” issue , as it has been dubbed by researchers at the Palo Alto Network, occurs when apps come from third-party sources, rather than from the official store, or when a user clicks on an ad. The bug occurs when the system application PackageInstaller installs APK files.
To exploit the vulnerability, the attacker uses a seemingly clean app to install malware in the future. They also disguise the actual permissions the app requires. Targeted users end up installing apps that are very different from the ones they approved before the installation process began.
The vulnerability has been patched for Android versions 4.3_r0.9 and later, but Palo Alto's Zhi Xu warned that some devices running Android 4.3 remain vulnerable. Google estimates that 49.9% of smartphonesare at risk. Palo Alto has released a scanning app that will show if a device is vulnerable.
Users should generally clean their devices of apps , and Google advises using the Play Store as their only source for downloading apps. This will help secure their devices and their security by checking the permissions that apps require to install and run.

