logo

Popular Android-based photo frames download malware on boot

ID: 1db6db3d-bee4-591b-a886-4a21339e96be

STIX ID: report--1db6db3d-bee4-591b-a886-4a21339e96be

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-13

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Uhale-branded Android digital photo frames contain multiple critical security flaws — including insecure TrustManager enabling MITM root RCE, command injection in updates, disabled SELinux/rooted devices, unauthenticated file upload service, hardcoded AES keys, and more — and researchers observed many frames automatically downloading and executing malicious JAR/DEX payloads at boot linked to Vo1d and Mzmess, creating a high-impact supply-chain compromise affecting devices sold under many brands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.