HomeSecurityXFO Vulnerability in Play Store Web App Domain

XFO vulnerability in Play Store Web App Domain

XFO Vulnerability in Play Store Web App Domain Allows Remote Code Execution

XFO Flaw Play Store Web App Domain

A security warning has been issued by security researchers about malicious users being able to install and launch arbitrary apps on the Play Store, by exploiting a cross-site scripting (XSS) or a universal cross-site scripting (UXSS) vulnerability in Google's app.

In a UXSS attack, client-side vulnerabilities are exploited in the web browser or web application, which can allow code execution, bypassing security mechanisms in the browser.

The vulnerability arises from the fact that the Play Store app does not include full support for X-Frame-Options (XFO), which is an HTTP header that indicates whether the web browser should be allowed to load a page in a frame.

Malicious actors often rely on this technique to trick users into believing that the content in an iframe comes from a trusted source.

The potential risk is aimed at users of JellyBean (4.3) and older versions of Android, which no longer receive official security updates for WebView.

Tod Beardsley of Rapid7, which maintains the Metasploit penetration testing tool, explained in a blog post on Tuesday that the browser on Android 4.3 and earlier has UXSS security vulnerabilities.

The researcher demonstrated with JavaScript and Ruby code that the response from the domain play.google.com can be generated without the appropriate XFO header.

To avoid being compromised by attackers exploiting the lack of XFO support, you can use a non-vulnerable web browser, such as Google Chrome, Mozilla Firefox , or Dolphin. Beardsley adds that logging out of your Google is also helpful, although this practice is highly unlikely to be adopted by the majority of users.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS