logo

Flaw Leaves 900M Android Devices Vulnerable

ID: c230380e-0a69-5cf5-8e12-5e8a38475935

STIX ID: report--c230380e-0a69-5cf5-8e12-5e8a38475935

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2013-07-05

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

**Executive Summary:** A Bluebox Security researcher disclosed a flaw in Android's application signing and verification that affects devices running Android 1.6 and later (an estimated ~900 million devices). The vulnerability allows modification of APK code without invalidating the cryptographic signature, enabling malicious applications to access device data and potentially compromise sensitive apps such as VPN clients; Google was notified but fixes depend on OEM firmware updates and user installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.