Geeks for your information
Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps (/showthread.php?tid=6454)



Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps - silversurfer - 01 April 19

Quote:Google is reporting an uptick in efforts by bad actors to plant potentially harmful applications (PHAs) on Android devices via pre-installed apps and by bundling them with system updates delivered over the air.
 
The technique is especially troubling, Google said, because PHAs are often malicious and users have no control over what comes pre-installed on their phone and what is downloaded via a system update.
 
“Malicious actors increased their efforts to embed PHAs into the supply chain using two main entry points: new devices sold with pre-installed PHAs and over the air (OTA) updates that bundle legitimate system updates with PHAs,” wrote Google in its Android Security and Privacy Year in Review 2018released on Friday.

SOURCE: https://threatpost.com/google-warns-of-growing-android-attack-vector-backdoored-sdks-and-pre-installed-apps/143332/


RE: Google Warns of Growing Android Attack Vector: Backdoored SDKs and Pre-Installed Apps - Deep900 - 02 April 19

That is a serious problem, especially for the fact they could be installed with system updates (which are fundamental also for new critical security updates, patches and fixes). In some cases preinstalled applications can be disabled with phone settings.