
Experts from Palo Alto Networks have discovered a vulnerability in the Android mobile operating system that allows them to seize full control of a device, install applications on it that attackers need, or disable it.
As CNews explains, the attack described by experts is a variation of the attack called “Cloak and Dagger,” which was described this spring by specialists from the University of California at Santa Barbara and the Georgia Institute of Technology. The essence of this attack is that the malicious application displays its own pop-up window on top of all windows, which disguises itself as real notifications from the operating system. For example, a program may request the device owner to gain access to various features and administrative privileges on the system.
At the same time, researchers have previously noted that malware attempting to carry out such attacks has a serious limitation - they must receive explicit permission to use the draw on top function, which allows an application to display its windows on top of others, and this feature is only available to applications from Google Play store.
However, Palo Alto Networks experts have found that Android system pop-up notifications, which are displayed on top of all windows, do not require special permissions from users and can be modified in such a way that the user mistakes them for regular application windows, can be used to carry out this type of attack. With this type of attack, malware does not require separate permissions and can be distributed outside of Google Play.
Researchers emphasize that the identified vulnerability is present in all versions of Android with the exception of Android 8.0 Oreo, introduced recently. It is also known that Google has begun distributing patches to fix the vulnerability. Users are advised to exercise caution and only install apps from Google Play on their devices.