Microsoft warns of "Dirty Stream" attack impacting Android apps
ID: aed1243e-6e7c-5d76-a5a1-94b9f6226fdc
STIX ID: report--aed1243e-6e7c-5d76-a5a1-94b9f6226fdc
Feed Name: Bleeping Computer
Microsoft disclosed a vulnerability dubbed 'Dirty Stream' in which malicious Android apps can abuse improperly implemented content providers and custom intents to send manipulated filenames or paths that cause target apps to write or execute files in sensitive directories, risking arbitrary code execution and data/secret theft. The researchers identified the pattern in apps representing over four billion installations (notably Xiaomi File Manager and WPS Office), worked with vendors to deploy fixes, and prompted Android/Google to update developer guidance; users are advised to keep apps updated and avoid untrusted APK sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
