
BlueBox Labs specialists revealed information about the vulnerability in Android, allowing attackers to access the functions of smartphones and tablets and stored on them personal data without the permission of the user, the CNews portal reports.
The vulnerability was discovered three months ago, and BlueBox Labs specialists informed Android developers from Google. The patch that eliminates the problem was released almost immediately, but this did not save the vast majority of owners of Android devices, since the problem was solved only in the latest version of the OS. Smartphones and tablets on which Android versions are installed, starting from 2.1 (Eclair) and ending with 4.3.1 (Jelly Bean), are not protected from unauthorized access.
The discovered vulnerability can pose a very serious threat, since with its help hackers can spread extremely harmful software. BlueBox analysts called her FAKE ID ("fake certificate"), because it allows you to deceive the system of digital application certificates and issue a malicious program for the application of an official supplier to whom the user has already allowed access to the system.
The technical director of the company Jeff Forestal described the essence of the discovered error on the Bluebox blog , civing an example of a situation where the robber approaches the guard and makes a fake pass, and he, looking at the false document, calmly lets the attacker into the building, without checking the authenticity of the pass.
So, the installed application can be disguised as a program created by Adobe Systems. The Android system installed on a smartphone or tablet does not check this fact and automatically gives the application by privileges available to official programs from Adobe. As a result, an attacker can easily introduce a malicious code into the system, hiding behind the Flash plugin.
According to Forestal, cybercriminals have the opportunity to use this vulnerability to obtain user data. Financial transactions performed using mobile payment applications, for example, through Google Wallet, were also threatened.
According to BlueBox experts, at the time of the detection of a vulnerability in the risk zone, 99% of the Android platform were on the risk zone, but the company has no evidence that the hackers managed to use it.