7 year old bug hauts Google Pixel devices

7 year old bug hauts Google Pixel devices


Researchers have discovered a critical vulnerability that has been surfaced within Pixel devices since 2017, potentially putting millions of Google Pixel users at risk.

The vulnerability stems within the pre-installed app with unnecessary system privileges, allowing attackers to inject malicious code and potentially take over devices.

The application is called Showcase.apk, designed for Verizon by Smith Micro that supposed to be used to turn Pixels into demo devices. However, it includes a backdoor that gives attackers a way to compromise the device.

Advertisements

The EDR capability of iverify identified an Android device revealed that the Showcase.apk Android application package makes the OS vulnerable to hackers, allowing man-in-the-middle attacks, code injection, and spyware. Showcase has held deep-rooted system privileges, including the alarming ability to execute code remotely and install software without user consent.

This vulnerability could result in data loss breaches and could allow attackers to hijack the app and gain complete control of the device. As it is not inherently malicious, security technology may overlook it, and the app is installed at the system level and part of the firmware image, making it uninstallable at the user level.

Showcase.apk is a system-level code that transforms a phone into a demo device, altering the operating system. It runs in a privileged context, causing issues such as not authenticating a domain, using unsecure default variable initialization, altering configuration files, handling non-mandatory files, and communicating insecurely with a predefined URL over HTTP.

Google said that it would inform other Android OEMs about the APK and pointed out that the Showcase app, owned by Verizon, is mandatory on all Android devices sold by Verizon.

Advertisements

It’s important to note that Showcase is disabled by default, requiring physical access to a device and knowledge of the system password to activate. But, the risk of  remote exploitation can not be ruled out, especially considering the sophistication of modern cyberattacks.

These preinstalled utilities become a liability: they are installed on many devices, they are hard to remove or disable, and they are not subject to the same security standards as the actual operating system. Hearing they are vulnerable, and that the vulnerability affects large numbers of users should come as no surprise. There is little point in promising seven years of security updates at the operating system level if it is going to be bundled with software that is unburdened by that promise,” he concluded

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.