New Android security flaw lets hackers seize control of apps — uninstall these immediately

Another day, another new Android malware strain. Microsoft is sounding the alarm about a recently discovered critical security vulnerability on Android named “Dirty Stream” that can let malicious apps easily hijack legitimate apps. Worse still, this flaw impacts multiple apps with hundreds of millions of installs. If you have one of the best Android phones, here’s what you need to know to protect your data.

The vulnerability relates to the ContentProvider system prevalent across many popular Android apps, which manages access to structured data sets meant to be shared between different applications. It’s basically what lets your Android apps talk to one another and share files. To protect users and ward off unauthorized access, the system includes safeguards such as strict isolation of data, unique permissions attached to specific URIs (Uniform Resource Identifiers), and path validation security.

What makes the Dirty Stream vulnerability so devious is how it manipulates this system. Microsoft has found that hackers can create “custom intents,” messaging objects that facilitate communication between components across Android apps, to bypass these security measures. By exploiting this loophole, malicious apps can send a file with a manipulated filename or path to another app using a custom intent, sneaking in harmful code disguised as legitimate files.

From there, a hacker could trick a vulnerable app into overwriting critical files within its private storage space — and the results can be devastating. As BleepingComputer put it, Dirty Stream essentially turns a common OS-level function into a weaponized tool to execute unauthorized code, steal data, and even hijack an app while the user is none the wiser.

“Arbitrary code execution can provide a threat actor with full control over an application’s behavior,” Microsoft said in a security bulletin this week. “Meanwhile, token theft can provide a threat actor with access to the user’s accounts and sensitive data.”

How widespread is this threat?

Microsoft’s investigation found that this vulnerability is not an isolated issue. The company uncovered incorrect implementations of the content provider system prevalent across many popular Android apps.

“We identified several vulnerable applications in the Google Play Store that represented over four billion installations,” Microsoft explained. “We anticipate that the vulnerability pattern could be found in other applications.”

Microsoft gives two examples of popular apps that were susceptible to this risk that have since been patched: Xiaomi Inc.’s File Manager (1B+ installs) and WPS Office (500M+ installs).

Given the nature of how this vulnerability works, it’s hard to know exactly how many other legitimate apps may have been impacted. But it’s safe to assume this potential risk is on an industrial scale until all apps are patched.

How to stay safe from Android malware

amazon, microsoft, android, new android security flaw lets hackers seize control of apps — uninstall these immediately

((Image credit: Google))

To steer clear of potentially harmful malware infecting your Android device, the first and easiest step is to avoid sideloading apps altogether. While it might seem convenient, and certain apps may require sideloading, the majority of people can find what they need on official app stores like Google Play Store, Samsung Galaxy Store, or Amazon Appstore.

The reason you don’t want to sideload apps is that they don’t go through the same stringent security checks that apps hosted on official stores do. This is why it’s crucial to rely on reputable sources for app downloads to keep your device safe from malware.

Next, you should ensure Google Play Protect is enabled on your Android smartphone. It comes pre-installed on most phones with the Play Store, and it actively scans both existing and newly downloaded apps for viruses. Likewise, you can also install one of the best Android antivirus apps for additional protection and extra features to help keep you safer online.

More from Tom’s Guide

    OTHER NEWS

    21 minutes ago

    Cardiff ease past 14-man Sharks in United Rugby Championship encounter

    21 minutes ago

    He’s been accepted to 122 colleges with $5.3 million in scholarships. His choice came down to his love of music

    21 minutes ago

    Ben Miller says private school pupils often look bored by his reading sessions...unlike state sector

    21 minutes ago

    MK PARTY ready to deliver its People’s Manifesto at Orlando Stadium

    21 minutes ago

    Russia and China ‘manipulating UK public opinion by promoting pro-Palestinian influencers’

    21 minutes ago

    Sharlene Mawdsley beats 400m Olympic qualification time

    21 minutes ago

    Benjamin Netanyahu Confronted With Ultimatum and Deadline

    21 minutes ago

    Israel War Cabinet Member Sets Ultimatum and Threatens to Quit Government

    22 minutes ago

    Getting the job done in Hamilton's return to Australia

    22 minutes ago

    An ultimatum raises pressure on Netanyahu to make postwar plans for Gaza, even as fighting rages

    28 minutes ago

    Olive oil prices skyrocket with bottles of extra virgin now hitting £20 each as costs soar 39 per cent in a year - while cash-strapped families battle to afford the weekly shopping bill

    28 minutes ago

    Shameless star Tina Malone reveals her war hero partner Paul Chase took his own life after he turned to drink and drugs to deal with the trauma of feeling 'lost' and 'useless'

    28 minutes ago

    Hero lecturer and veteran army nurse is hailed a hero for leaping into action to save man 'suffering a heart attack' on Alicante to Newcastle flight - as he tells pilot to divert easyJet plane to France

    29 minutes ago

    West Bengal Lok Sabha election phase 5: Key fights, constituencies

    29 minutes ago

    Barbra Fuller, Star of Republic Pictures and ‘One Man's Family' on the Radio, Dies at 102

    29 minutes ago

    Anthony Joshua sits beside Cristiano Ronaldo at ringside to watch Fury vs Usyk

    29 minutes ago

    Harry Kane sees ANOTHER trophy chance slip through fingers on final day of Bundesliga

    29 minutes ago

    Soccer-Bayern end poor season in third place after Hoffenheim loss

    30 minutes ago

    Jürgen Klopp’s Liverpool rescued the league from brand-busting monotony

    30 minutes ago

    Donald Trump makes embarrassing gaffe as he confuses his criminal trials during speech

    30 minutes ago

    Soccer-Leverkusen have no time to soak in 'Neverlusen' season

    30 minutes ago

    Man Utd injuries: Every player ruled out of Brighton clash

    30 minutes ago

    'We want it over', says Mueller after Bayern hit 13-year low

    30 minutes ago

    “I know he did a lot of things wrong” - Mark Aguirre saw a different side of the controversial Roy Tarpley

    30 minutes ago

    Joey Gallo returns, but Nats endure another quiet offensive night

    30 minutes ago

    Atalanta not afraid of Bayer 'Neverlusen', Gasperini says

    31 minutes ago

    FEMA now accepting applications for disaster relief

    31 minutes ago

    Orlando Bloom Absolutely Hated A Huge Role - 'I Didn't Want To Do The Movie'

    32 minutes ago

    Imprisoned Oregon man charged in deaths of three women found in Portland area last year

    33 minutes ago

    Casey Wilson Talks ‘Happy Endings’ Revival Plans As She Launches Podcast With Adam Pally

    37 minutes ago

    McDonald’s franchisee claims company is trying to boot him from his 37 locations: ‘Wrongfully scheming’

    37 minutes ago

    This modder proves everything’s better with a GBA SP screen attached

    37 minutes ago

    AC Milan Travel To Meet Torino As The Season Wraps Up

    37 minutes ago

    Will Lionel Messi play for Inter Miami against DC United today? Injury update

    37 minutes ago

    Pakistan, India urge citizens in Kyrgyzstan to stay inside

    37 minutes ago

    Why the Spurs should use both of their top ten draft picks

    37 minutes ago

    'One nation with one heart': October 7 survivors share stories with UK young professionals

    37 minutes ago

    Rise of neo-fascist groups in Italy, Mussolini legacy still resonates with some

    38 minutes ago

    Fulham: Kenny Tete new contract talks stall as clock ticks down on current deal

    38 minutes ago

    Very special to equal Senna pole record - Verstappen

    Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch