Popular Android-based photo frames download malware on boot
ID: 1db6db3d-bee4-591b-a886-4a21339e96be
STIX ID: report--1db6db3d-bee4-591b-a886-4a21339e96be
Feed Name: Bleeping Computer
Uhale-branded Android digital photo frames contain multiple critical security flaws — including insecure TrustManager enabling MITM root RCE, command injection in updates, disabled SELinux/rooted devices, unauthenticated file upload service, hardcoded AES keys, and more — and researchers observed many frames automatically downloading and executing malicious JAR/DEX payloads at boot linked to Vo1d and Mzmess, creating a high-impact supply-chain compromise affecting devices sold under many brands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
