Connect with us

Hi, what are you looking for?

Android

Vulnerability allows one-click modification of Android apps

Trend Micro’s Mobile Threats Research team has discovered a vulnerability in the Apache Cordova app framework (used to develop Android apps) that allows potential attackers to modify the appearance and behavior of apps just by clicking a specially-crafted URL.

This vulnerability is notable because 5.6% of all apps in Google Play are developed using Cordova and are now potentially affected.

The vulnerability is easily exploitable as it simply requires tricking the user into clicking a specially crafted URL. It allows app modification such as the appearance and functionalities. It can also inject popup screens and messages, and even remotely crash the apps by injecting special data into the intent bundle.

Designated as CVE-2015-1835, this high-severity vulnerability affects all versions of Apache Cordova up to 4.0.1. Apache has released a security bulletin confirming the vulnerability and a newer version 4.0.2 of Cordova Android to address these security issues.

Trend Micro strongly suggests Android app developers upgrade their Cordova framework to the latest version (version 4.0.2) and rebuild to a new release. This will prevent apps from being modified by attackers targeting this vulnerability.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

SOFTWARE

Smoothness lies at the heart of OriginOS 6— more than a feature, it represents a new standard of mastery.

HEADLINES

Cybersecurity firm Trend Micro Philippines is raising awareness on the need for proactive security measures that will prepare defenders of AI systems, improve risk...

HEADLINES

Trend Research uncovers a sprawling global criminal infrastructure that impersonate legitimate companies, exploit trusted communications channels, and prey on job seekers using gamification techniques.

HEADLINES

“At the heart of every DECODE conference is a commitment to address the critical cybersecurity skills gap that continues to widen globally and locally....

HEADLINES

Trend’s Digital Twin capabilities will empower enterprises to simulate real-world cyber threats, validate their defenses, and adapt policies in real time across complex and...

White Papers

Hyper-personalized attacks and agent AI subversion will require industry-wide effort to root out and address. Business leaders should remember that there’s no such thing...

HEADLINES

Trend's 2025 predictions report warns of the potential for malicious "digital twins," where breached/leaked personal information (PII) is used to train an LLM to...

HEADLINES

Trend's flagship ESP product, Trend Vision One – Email and Collaboration Security, is seamlessly integrated as part of a comprehensive ASRM and XDR platform...

Advertisement