IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Android apps still vulnerable to a major bug despite an existing patch

Millions of users at risk from a flaw in the Google Play core library

Security researchers have found major Android apps used by hundreds of millions of people, such as Grindr, Bumble, OKCupid, Cisco Teams, Moovit, Yango Pro, Edge browser, and many others, are vulnerable to a known flaw that could give attackers access to the app users’ phones and data.

According to research, the security flaw is in Google’s widely used Play core library, which lets developers push in-app updates and new feature modules to their Android apps.  Google fixed the flaw in April 2020, but the app developers must also install the updated Play core library in their apps to eliminate the threat. Many developers have not yet done this.

The Play core library is the app’s runtime interface with the Google Play Store, impacting how an app interacts with Google Play Services. These interactions include dynamic code loading (e.g., downloading additional levels only when needed), delivering locale-specific resources, and interacting with Google Play’s review mechanisms.

Researchers said that if exploited, the flaw could allow a hacker to inject malicious code into a vulnerable application and get access to all the same data that the application has.  For example, it could allow hackers to steal authentication codes or grab users’ credentials from banking apps. A hacker could target vulnerable dating applications to spy on victims or grab the messages they send and receive from the app.

While Google acknowledged and patched the bug on April 6, 2020, rating it an 8.8 out of 10 for severity, developers need to push the patch into their respective applications to mitigate the threat fully. In September 2020, 13% of Google Play applications analyzed by Check Point researchers used the Google Play Core library, and 8% used the vulnerable version.

Aviran Hazum, Check Point’s mobile research manager, said researchers estimated hundreds of millions of Android users are at risk.

“Although Google implemented a patch, many apps are still using outdated Play Core libraries. The vulnerability CVE-2020-8913 is highly dangerous. If a malicious application exploits this vulnerability, it can gain code execution inside popular applications, obtaining the same access as the vulnerable application,” he said. “The attack possibilities here are only limited by a threat actor’s imagination.”

Featured Resources

Activation playbook: Deliver data that powers impactful, game-changing campaigns

Bringing together data and technology to drive better business outcomes

Free Download

In unpredictable times, a data strategy is key

Data processes are crucial to guide decisions and drive business growth

Free Download

Achieving resiliency with Everything-as-a-Service (XAAS)

Transforming the enterprise IT landscape

Free Download

What is contextual analytics?

Creating more customer value in HR software applications

Free Download

Recommended

Qualcomm and Mediatek flaws left millions of Android users at risk
Security

Qualcomm and Mediatek flaws left millions of Android users at risk

22 Apr 2022
Best smartphone 2022: The top handsets from Apple, Samsung, Google and more
Mobile

Best smartphone 2022: The top handsets from Apple, Samsung, Google and more

8 Apr 2022
Google will cull out-of-date Play store apps in bid to improve Android security
Google Android

Google will cull out-of-date Play store apps in bid to improve Android security

7 Apr 2022
Businesses on alert as mobile malware surges 500%
mobile security

Businesses on alert as mobile malware surges 500%

10 Mar 2022

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
Europe's first autonomous petrol station opens in Lisbon
automation

Europe's first autonomous petrol station opens in Lisbon

23 May 2022
Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers
ransomware

Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers

26 May 2022