logo

iVerify Discovers Android Vulnerability Impacting Millions of Pixel Devices Around the World

ID: 67d6622d-f26d-5105-bfc5-788913a2fa40

STIX ID: report--67d6622d-f26d-5105-bfc5-788913a2fa40

Feed Name: iVerify Blog

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

iVerify discovered that a preinstalled system app, Showcase.apk (developed by Smith Micro), shipped on many Google Pixel devices since September 2017, fetches a configuration over unsecured HTTP and runs with excessive system privileges; this allows remote code execution, remote package installation, and exposes devices to MITM-based code injection and spyware. The app cannot be removed by users, may be enabled via methods requiring access, and Google has not yet provided a patch following iVerify's disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.