Android 14 apps may limit malicious apps from accessing content to improve security
#1
Information 
Quote:[Image: android-14.png]

This year's Android update, Android 14, includes a new option for Android apps to prevent malicious apps from accessing their content. The move is designed to improve security, especially for important applications such as authenticator apps, brokerage apps, and other apps that are of a sensitive nature.

Content stealing malware, for instance those aimed at stealing two-factor authentication codes, are not as common as other types on Android, but there have been cases in the past. To gain access to another application's data, malware apps have used the Accessibility service in the past.

Legitimate accessibility apps, like screen readers or narrators, need access to other apps to assist Android users who require them. They help navigate apps and inform users about what is happening on the screen. This powerful feature set has been used by malicious apps in the past.

[Image: android-14-preview.jpg]

Google implemented changes in previous versions of Android to limit these dangers. In Android 12, it introduced a new attribute for apps, which they needed to declare, if they included accessibility functionality. Apps without the declaration could not be uploaded to Google Play anymore.

Then, in Android 13, Google hammered down on the use of Accessibility functionality in sideloaded apps. It was a logical consequence, after having introduced the new attribute in Android 13. This new restriction made it harder for malicious apps to trick users into enabling Accessibility functionality, but it was still possible. In essence, Google limited the option to enable Accessibility functionality for sideloaded apps.

Now, in Android 14, comes the next limitation. Application developers may enable a new setting in their application, which limits access to Accessibility tools that have declared their status. The change prevents non-Store apps from using Accessibility functionality to access an application's data.

While it is still possible that malicious apps with the right declaration pass the Google Play protections to be offered there, it is limiting malicious apps that use Accessibility functionality significantly. Clearly, the change is also limiting apps that are not malicious from making use of accessibility features.

One of the downsides of the change in Android 14 is that apps need to have the feature enabled. There is a good chance that many high security apps will implement it to improve security further, but it will take some time before the majority of these apps have implemented the change. Also, since it requires Android 14, many users of Android won't benefit from the change unless the new version is offered for their device.
...
Continue Reading
Reply


Messages In This Thread
Android 14 apps may limit malicious apps from accessing content to improve security - by harlan4096 - 14 April 23, 08:32

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.0  LanguageT...Kool — 08:39
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 04:41
Surfshark VPN : Award-winning VPN servi...
Surfshark launches...jasonX — 03:43
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31

[-]
Birthdays
Today's Birthdays
avatar (41)alapesihy
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>