Google's Android operating system is the most popular mobile OS, but also the most targeted when it comes to mobile malware.
In fact, mobile security researchers at FireEye have discovered that even some apps that have normal permission levels could easily turn out to be malicious, since they can modify icons on the home screen without any warning.
The researchers say that such an application could change the actual icons to redirect users to phishing websites or to the malicious application itself, which they would do without any warning to the user.
However, the dangerous permissions that appear to the user ask for their approval before being applied, while the legitimate ones are installed automatically, without asking for approval.
The team says the app has been tested on Android 4.4.2. Google Play will accept such an app and users will not be warned when downloading and installing it (both the app and the website that redirected users have been removed).
Apparently, the vulnerability doesn't just affect Android devices running AOSP.
However, Google stated that it has acknowledged this issue and has already released an update.
