Old Apache Code at Root of Android FakeID Mess
ID: ca2ff306-226f-5e28-b419-58a4ea3c4b9f
STIX ID: report--ca2ff306-226f-5e28-b419-58a4ea3c4b9f
Feed Name: Security Ledger
Bluebox Security disclosed the 'FakeID' vulnerability in Android (affecting Android 2.1 through 4.4) that stems from improper certificate-chain verification in package installer code derived from Apache Harmony. An attacker can craft an app whose certificate claims to be issued by a trusted vendor (e.g., Adobe), enabling silent privilege escalation and access to sensitive device resources; Google released a patch and mitigations (Google Play/Verify Apps), but many devices may remain unpatched due to ecosystem fragmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
