Users of Popular Android Applications Risk Getting Compromised Via Highly Privileged Device Migration Tools
ID: e2239f51-bfad-5596-9b46-4fcc20108f00
STIX ID: report--e2239f51-bfad-5596-9b46-4fcc20108f00
Feed Name: CloudSEK Blog
Threat Score
CloudSEK researchers discovered that default device-migration/clone utilities on ColorOS-based phones (Realme/Oppo/OnePlus) can copy app data and session credentials to a new device without invalidating session cookies, enabling account takeover—including bypassing WhatsApp 2FA—if an attacker gains temporary physical access to an unlocked phone; the report provides a PoC, a list of affected apps, impact analysis, and mitigations (lock device, 2FA, review permissions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
