Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"An attacker can exploit these vulnerabilities using a malicious app. These apps require no special permissions to take advantage of these vulnerabilities, alleviating any suspicion users may have when installing."

So If I understand correctly, it does require you to side-load an app. Can I assume Google Play apps are "safe", at least from this type of vulnerabilities?



> Can I assume Google Play apps are "safe", at least from this type of vulnerabilities?

Looking at the crap that is on the play store, I wouldn't count on it.


"crap" aside, users of the Play store (as well as Apple's App Store) are overwhelmingly safe.

Google now has Android Security Annual reports [0]. From that you can see that if you only use the Play Store (no sideloading), only 0.15% of devices got a potentially harmful app.

On top of Play Store's security features, if there were a malicious app that began causing trouble, Google has other mechanisms to shut down PHAs. As this vulnerability shows there are issues that are outside AOSP, Android has been shoring up more defenses in depth.

[0] https://security.googleblog.com/2016/04/android-security-201...


Overwhelmingly safe in the sense that tons of popular apps impede and undermine your security and privacy, especially easily if you're never getting updated to Marshmallow.

https://www.engadget.com/2016/03/19/ftc-issues-warning-to-ap...


I only install very very mainstream apps from major well known authors on my phone. Mostly only from Google but a few others such as Firefox, Netflix, SoundCloud.


If I understand correctly, the exploit needs no special privileges to run the exploit code. Google Play doesn't vet apps before they go up, they take down apps in response to complaints. So no it's not safe, but I'd (maybe naively) expect them to notice a dangerous app pretty quickly.


Google Play does vet apps before they go up. They have several mechanisms to analyze apps before they are published in the app store. Look up Google Bouncer.

This said, it is not clear that their analysis would catch apps that try to exploit these vulnerabilities.


> This said, it is not clear that their analysis would catch apps that try to exploit these vulnerabilities.

I would hazard a guess that right now there a bunch of people at Google making sure that it does.


I could have sworn that all apps are run inside a test environment before allowed onto the store. But the process is automated and likely will not catch novel attacks.


This is correct, they do now test apps before they go up. But yeah, plenty of malware is regularly found in the Play Store, so you can't just "trust Google" to protect you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: