Jump to content

Android FakeID vulnerability....


ross549

Recommended Posts

https://securityledger.com/2014/07/old-apache-code-at-root-of-android-fakeid-mess/

 

The vulnerability was disclosed on Tuesday. It affects devices running Android versions 2.1 to 4.4 (“KitKat”), according to a statement released by Bluebox. According to Bluebox, the vulnerability was introduced to Android by way of the open source Apache Harmony module. It affects Android’s verification of digital signatures that are used to vouch for the identity of mobile applications, according to Jeff Forristal, Bluebox’s CTO. He will be presenting details about the FakeID vulnerability at the Black Hat Briefings security conference in Las Vegas next week.

 

In an email statement to The Security Ledger, a Google spokesman acknowledged working with Bluebox to fix the vulnerability. “After receiving word of this vulnerability, we quickly issued a patch that was distributed to Android partners, as well as to AOSP,” he wrote. “Google Play and Verify Apps have also been enhanced to protect users from this issue. At this time, we have scanned all applications submitted to Google Play as well as those Google has reviewed from outside of Google Play and we have seen no evidence of attempted exploitation of this vulnerability.”

 

Hopefully this gets pushed out FAST. :)

 

Adam

  • Like 3
Link to comment
Share on other sites

securitybreach

That and of course, Nexus devices get the updates right away.. Or you can run AOSP(Android OpenSource Project) roms and get the updates as well.

Link to comment
Share on other sites

but aren't phone companies notorious for never or rarely patching their os?

(yes, android does other things besides phone...)

 

Yes, LG, Samsung, and others are generally slow to push major updates. Making it harder are the cellular carriers that have their own specific configuration and software. I am not sure about security fixes, though.

 

Adam

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...