Introducing Zscaler's Android Vulnerability Scanner
ID: 5822b67d-555f-5291-979b-66f847eecbb0
STIX ID: report--5822b67d-555f-5291-979b-66f847eecbb0
Feed Name: Zscaler Security Research Blog
The report details the Android "master key" vulnerability which allows attackers to insert duplicate classes.dex and AndroidManifest.xml files into APKs so malicious code and additional permissions execute at runtime without breaking the original app signature. The issue affects most current Android implementations and requires vendor-specific patches, and the document notes that malicious apps exploiting the flaw have been seen in the wild and that Zscaler provides a free APK scanner to detect such exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
