logo

Users of Popular Android Applications Risk Getting Compromised Via Highly Privileged Device Migration Tools

ID: e2239f51-bfad-5596-9b46-4fcc20108f00

STIX ID: report--e2239f51-bfad-5596-9b46-4fcc20108f00

Feed Name: CloudSEK Blog

Threat Score
50/100

Date Published: 2023-04-28

Date Updated: 2026-04-27

...
...

CloudSEK researchers discovered that default device-migration/clone utilities on ColorOS-based phones (Realme/Oppo/OnePlus) can copy app data and session credentials to a new device without invalidating session cookies, enabling account takeover—including bypassing WhatsApp 2FA—if an attacker gains temporary physical access to an unlocked phone; the report provides a PoC, a list of affected apps, impact analysis, and mitigations (lock device, 2FA, review permissions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.