77% of Android Devices Still Endanger Users Due to Design Flaws

Researchers have discovered a design flaw in Android that can be used to remotely capture screenshots or record audio… without the user’s knowledge or consent.

The attack relies on the MediaProjection service in Android, which has these extensive capabilities, and was made available for the use of non-propriety apps since Android version 5.0 (Lollipop). While apps are required to receive the user’s permission to use this service, the new attack uses a screen overlay tactic to deceive them into granting it unknowingly.

At the time of publication, Google has only fixed the issue in Android version 8.0 (Oreo), leaving Android versions 5.0, 6.0 and 7.0, which account for roughly 77.5% of Android devices, vulnerable.

How the Vulnerability Operates

Unlike other permission requests in Android, such as access to contacts or location, the MediaProjection service does not have a dedicated permission window for the user to grant access. Instead, when an app attempts to use it, a different window appears, called a SystemUI popup. As the researchers discovered, an app can detect when this window is about to appear, and display a crafted message of its own which will cover the SystemUI popup and persuade the user to grant the permission to the sensitive MediaProjection service, unaware of the scheme.

Once the app gained the necessary permissions, it can then record the device’s screen and audio, making it the ultimate spying tool. The attack is not completely covert however, as a notification of the recording activity will appear in the notification bar, though most users are not likely to understand its true meaning.

The second part of the attack consists of a screen overlay tactic, often called “clickjacking”, which is a very common method used by mobile malware, especially banking malware and ransomware. While Google has made significant effort to mitigate this tactic, it is still a successful way to deceive users and gain their credentials.

Why This Is a Problem

This is not the first time such a design flaw has been discovered. As we wrote in the past, the Android Accessibility service, which is meant to help users with disabilities, was abused to grant attackers extensive permissions by using a similar tactic of displaying a fake overlay page.

While researchers also initially discovered this flaw, malware was soon spotted using it in the wild for their own malicious purposes. The main problem with vulnerabilities that originate in inherent design flaws is that they are usually much harder to get rid of.

On the one hand, Google does not want to eradicate the use of the service altogether, but on the other, it clearly cannot allow the same architecture to operate. Since the Android Operating System is complex, and the services are intrinsic and crucial for many processes, it is hard to adapt the code so that it is both secure and allows for an agile operation.

How To Stay Protected   

To stay secure from both the recent attack discovered, and from the wide landscape of mobile malware, users should use advanced security measures capable of detecting and blocking any attempt to display a fake overlay window or conduct any malicious activity by using dynamic analysis and ascertaining the context of the activity.

The post 77% of Android Devices Still Endanger Users Due to Design Flaws appeared first on Check Point Blog.



from Check Point Blog http://ift.tt/2zD2fjg

Amazon steps up pace in artificial intelligence race

LAS VEGAS (Reuters) - Amazon.com Inc this week announced a flurry of new machine learning features for its Amazon Web Services cloud computing business, raising its challenge to Silicon Valley's biggest tech firms for the lead in artificial intelligence.


from Reuters: Technology News http://ift.tt/2iv7deS

Qualcomm files new patent infringement complaints against Apple

(Reuters) - Qualcomm Inc said on Thursday it filed three new patent infringement complaints against Apple Inc , saying there were 16 more of its patents that Apple was using in its iPhones.


from Reuters: Technology News http://ift.tt/2AiKoBB

Now hiring? Amazon says its voice aide Alexa is ready for the office

(Reuters) - Amazon.com Inc wants to be your new executive assistant at work.


from Reuters: Technology News http://ift.tt/2i5bEcy

GM plans large-scale launch of self-driving cars in U.S. cities in 2019

SAN FRANCISCO/DETROIT (Reuters) - General Motors Co laid out its vision for self-driving vehicles on Thursday, telling investors it planned a commercial launch of fleets of fully autonomous robo-taxis in multiple dense urban environments in 2019, in a challenge to rivals such as Alphabet Inc's Waymo.


from Reuters: Technology News http://ift.tt/2ArS8l8

Ex-Autonomy executive cuts deal with U.S. in HP fraud probe

BOSTON (Reuters) - A former executive at British software company Autonomy has agreed to become a cooperating witness to resolve U.S. charges that he and others schemed to deceive investors about the firm's performance before its sale to Hewlett Packard in 2011.


from Reuters: Technology News http://ift.tt/2AtddMc

WhatsApp service resumes after worldwide outage

SAN FRANCISCO (Reuters) - Popular messaging app WhatsApp said on Thursday that users around the world had been unable to access its service for a brief period, but that access for its 1 billion daily users had since resumed.


from Reuters: Technology News http://ift.tt/2Bz3tO1

Integrating with Amazon GuardDuty

We’re thrilled to be continuing our long-running partnership with AWS with several new announcements designed to allow for tighter integration; more effective, automated security; and lower operational overheads.

Click here to view more.

Amazon GuardDuty has just launched! Trend Micro’s integration with Amazon GuardDuty will automatically improve the protection of EC2 and ECS workloads, increasing visibility and reducing operational overheads for organizations.

To hear more, check out this video with our AWS Community Hero, Mark Nunnikhoven; @marknca.



from Trend Micro Simply Security http://ift.tt/2zDF4pm

Goldman eschews bitcoin but wants to help clients crypto-trade

NEW YORK (Reuters) - Goldman Sachs Group Inc is trying to figure out how to cater to investors who want to trade bitcoin even though the digital currency remains too volatile for the Wall Street bank to trade itself, according to comments by a representative and its chief executive officer on Thursday.


from Reuters: Technology News http://ift.tt/2iuQI2i

FDA clears first medical device accessory for Apple Watch

(Reuters) - The U.S. Food and Drug Administration on Thursday cleared a device embedded in an Apple Inc watch band that monitors a user's heart rate, detects when something is amiss and prompts the user to take an electrocardiogram.


from Reuters: Technology News http://ift.tt/2jyLQFS

Verizon plan to launch 5G broadband lifts shares

NEW YORK (Reuters) - Verizon Communications Inc shares rose 2 percent in midday trading on Thursday after the No. 1 U.S. wireless carrier said it would launch next-generation high-speed Internet services in three to five U.S. markets in 2018.


from Reuters: Technology News http://ift.tt/2zSStOw

Netflix Phishing Campaign Login and Billing Information

A common method for Phishing, used in malspam campaigns, is the use of hyperlinks inside such a seemingly valid entity, in order to direct the victim into a designated website controlled by the attacker or in order to make the user divulge confidential information.

from Check Point Update Services Advisories http://ift.tt/2j3Rel1

Dialog shares tank on report Apple to design own power chips

FRANKFURT (Reuters) - Apple is designing its own power-management chips for use in iPhones as early as 2018, the Nikkei business daily reported on Thursday, triggering a more than 20 percent slide in shares of supplier Dialog Semiconductor.


from Reuters: Technology News http://ift.tt/2BnTI4f

'Bomb on board' wi-fi network causes Turkish Airlines flight to be diverted

ANKARA (Reuters) - A Turkish Airlines flight from Nairobi to Istanbul was diverted after the detection of a wi-fi network called "bomb on board" that alarmed the passengers, the airline said on Thursday.


from Reuters: Technology News http://ift.tt/2j4v0PF

Juniper shares drop after Nokia denies takeover chatter

(Reuters) - Shares of Juniper Networks Inc fell 8 percent in pre-market trade on Thursday after Finland's Nokia denied reports that it was in talks to buy the U.S. network gear maker.


from Reuters: Technology News http://ift.tt/2nhSVQ7

Spotify investor favors spring listing

HELSINKI (Reuters) - Venture Capital firm Northzone, one of the largest stakeholders in Spotify, would like to see the music streaming company's flotation in the spring, depending on market sentiment, one of its partners said on Thursday.


from Reuters: Technology News http://ift.tt/2jxEYJ3

De deepfakes a SMS falsos: Golpes digitais explodem no Brasil, alerta relatório

Metade dos brasileiros sofreu algum tipo de golpe digital em 2024 , segundo relatório da empresa de segurança BioCatch publicado nesta se...