Android SDK Flaw Could Enable Dropbox Data Theft
ID: 42ef465b-13db-5775-af3b-cf70bce8bd62
STIX ID: report--42ef465b-13db-5775-af3b-cf70bce8bd62
Feed Name: Security Ledger
Researchers at IBM X-Force disclosed CVE-2014-8889, a serious authentication flaw in Dropbox's Android SDK (versions 1.5.4–1.6.1) which could allow attackers to manipulate the INTERNAL_WEB_HOST parameter and expose a session nonce, tricking apps into syncing user data to attacker-controlled Dropbox accounts; Dropbox patched the SDK in 1.6.2 and notified major developers. The issue's impact is constrained — users running the official Dropbox Android app are not vulnerable, exploitation requires targeted conditions, and there is no report of widespread or active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
