Billions of Android Devices Open to 'Dirty Stream' Attack
ID: 3070871d-ce88-5611-b08e-ec3e3df914de
STIX ID: report--3070871d-ce88-5611-b08e-ec3e3df914de
Feed Name: Dark Reading
Microsoft researchers disclosed a common Android content-provider vulnerability that lets a malicious app send crafted filenames to consuming apps, which may blindly use those filenames to create or overwrite files in their private data space—potentially leading to authentication token theft, configuration manipulation, or remote/native code execution. The issue affects many apps (including some with hundreds of millions to over a billion installs); Microsoft coordinated disclosure with Google and vendors, and Google published developer guidance while some vendors have issued fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
