Connect with us

Hi, what are you looking for?

Android

Vulnerability allows one-click modification of Android apps

Trend Micro’s Mobile Threats Research team has discovered a vulnerability in the Apache Cordova app framework (used to develop Android apps) that allows potential attackers to modify the appearance and behavior of apps just by clicking a specially-crafted URL.

This vulnerability is notable because 5.6% of all apps in Google Play are developed using Cordova and are now potentially affected.

The vulnerability is easily exploitable as it simply requires tricking the user into clicking a specially crafted URL. It allows app modification such as the appearance and functionalities. It can also inject popup screens and messages, and even remotely crash the apps by injecting special data into the intent bundle.

Designated as CVE-2015-1835, this high-severity vulnerability affects all versions of Apache Cordova up to 4.0.1. Apache has released a security bulletin confirming the vulnerability and a newer version 4.0.2 of Cordova Android to address these security issues.

Advertisement. Scroll to continue reading.

Trend Micro strongly suggests Android app developers upgrade their Cordova framework to the latest version (version 4.0.2) and rebuild to a new release. This will prevent apps from being modified by attackers targeting this vulnerability.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Local IT and cybersecurity professionals came together for a full day of networking, talks, panel discussions, and hands-on activities that highlighted how fusing technologies...

HEADLINES

Enhanced with new management and operational tools designed specifically for Managed Service Providers (MSPs), the platform simplifies risk management for enterprises while also allowing MSPs...

HEADLINES

For this year’s conference, Trend Micro will highlight the pressing need to fuse together and integrate different technologies to produce holistic and multi-faceted solutions...

HEADLINES

Trend Micro research shows that cybercriminals are catching on to the explosion of enterprise AI use, resulting in a dramatic increase in AI-based tools available...

White Papers

The report warns that attackers are using more advanced methods to target fewer victims with the potential for higher financial gains.

HEADLINES

Robert McArdle, a leader in Trend Micro’s cybercrime research team and collaborator with the Federal Bureau of Investigation (FBI) and National Crime Agency (NCA),...

Biz Solutions

Trend Micro offers a suite of security solutions made for specific threats. 

HEADLINES

The widespread availability and improved quality of GenAI, coupled with the use of Generative Adversarial Networks (GANs), are expected to disrupt the phishing market...

Advertisement