Pre-Installed Android Apps Hide Serious Security Vulnerabilities

A new study by security firm Kryptowire reveals that pre-installed apps on Android devices from 29 vendors contain 146 security vulnerabilities. These hidden flaws allow attackers to silently install apps, record audio, and alter system settings.

Pre-installed apps on Android phones often annoy users with their clunky interfaces and difficulty to remove, but a new study reveals they actually pose significant security risks. Security firm Kryptowire builds a tool that automatically scans devices for shortcomings, and in a study funded by the U.S. Department of Homeland Security, they test phones from 29 different vendors. The researchers discover 146 vulnerabilities in total across both lesser-known brands and big names like Asus, Samsung, and Sony.

These security holes allow for a frightening range of unauthorized actions, from forcing the installation of other apps to silently recording audio or modifying system settings. While some vulnerabilities require access to other pre-installed apps to trigger, others can be exploited by any app a user chooses to download later. This wide attack surface puts millions of device owners at risk of data theft and privacy invasions through software they never wanted in the first place.

Google is aware of this supply chain threat and launches the Build Test Suite (BTS) in 2018 to scan partner firmwares for these Potentially Harmful Applications. In its first year, the BTS successfully prevents 242 compromised builds from reaching the ecosystem. However, automated systems cannot catch every flaw, and when a vulnerability slips through, there is no guarantee that manufacturers will ever provide a necessary patch to fix the issue.

Read More at the original source →