77% of Android Devices Still Endanger Users Due to Design Flaws
Researchers have discovered a design flaw in Android that can be used to remotely capture screenshots or record audio… without the user’s knowledge or consent. The attack relies on the MediaProjection service in Android, which has these extensive capabilities, and was made available for the use of non-propriety apps since Android version 5.0 (Lollipop). While apps are required to receive the user’s permission to use this service, the new attack uses a screen overlay tactic to deceive them into granting it unknowingly. At the time of publication, Google has only fixed the issue in Android version 8.0 (Oreo), leaving Android versions 5.0, 6.0 and 7.0, which account for roughly 77.5% of Android devices, vulnerable. How the Vulnerability Operates Unlike other permission requests in Android, such as access to contacts or location, the MediaProjection service does not have a dedicated permission window for the user to grant access. Instead, when an app attempts to use it, a different win...