Social Icons

Wednesday, May 10, 2017

Android O To Fix Major Security Flaw Debuted By Marshmallow

Android O will eliminate a major security vulnerability of Google’s omnipresent operating system that was introduced by Android 6.0.1 Marshmallow, cyber security firm Check Point claims. The flaw that enables a wide variety of malware is connected to the SYSTEM_ALERT_WINDOW permission that provides apps with the ability to overlay content over other apps without specifically notifying the user that they’re writing on the screen. The very nature of the permission makes it a serious security risk if it’s accidentally granted to a malicious app, though the main problem lies in the fact that the permission is de facto granted to all apps that are downloaded from the Google Play Store as of Android 6.0.1.

The Mountain View-based tech giant reportedly opted to facilitate the process of granting the permission due to the fact that non-malicious apps who legitimately needed it often weren’t able to function in an optimal manner as users would fail to grant them authorization in the system settings of their devices. While the Alphabet-owned company implemented certain safeguards that were designed to prevent the abuse of its mechanism, hackers reportedly still managed to find several ways to trick or completely bypass Google’s security measures and have their malware-enabling apps featured on the Google Play Store. The aforementioned permission was abused by 74 percent of Android ransomware and 57 percent of adware-infused apps on the Google Play Store, Check Point claims. Due to that state of affairs, Google will be patching the vulnerability related to the problematic permission by shipping Android O with TYPE_APPLICATION_OVERLAY, a new type of permission that will serve as an alternative to its predecessor but also prevent apps from overlaying any kind of data over “critical system windows.”

While the wording of the announcement doesn’t necessarily suggest that the Alphabet-owned Internet giant will be radically changing the process of granting the SYSTEM_ALERT_WINDOW permission, it seems that the company is still adamant to address the vulnerability by replacing the problematic authorization with a much more restrictive one whenever possible. By doing so, the company would minimize the chances of Android users falling victim to ransomware, adware, and other types of malware even if they accidentally download and authorize a malicious app.

Source :

No comments:

Post a Comment

Learn Python For Beginners

Category Of Mobile Courses

Actualités (644) Adsense (1) Affiliation (1) Algebraic Topology (2) Algorithmic (1) all-news (30) Android (5) Android App (8) Android app without code (4) Android Apps (256) Android Development (4) Android download (2) Android OS (3) AngularJS (1) Automata theory and formal language (5) Bootstrap CSS (1) C programming (5) Category and Functor (8) CMS (3) Computer Glossary (29) Create Mobile App With Ionic Framework (2) CSS (2) CSS-Cascading-Style-Sheets (4) Developpement Java (13) Differential Geometry (1) Django-Python-Framework (15) dropshiping (26) Earn Money by Internet (4) Emplois (23) Framework php (2) Fraud (2) Github (2) HTML (9) IT News (3) Java For Beginners (10) Javascript (12) Kotlin Programming Language (8) Kotlin For Mobile Android (1) Linux Download (2) Marketing (5) Mobile (3) Mobile Courses (4) Mobile Marketing (4) MoneyGram (1) News (721) Node.js (5) Open Source (1) Photoshop (1) Protect Computer (1) Python (37) Python BeautifulSoup (1) Python For Data Science (2) Python PyQt (14) Python Reference (1) Python Source Code (19) Python-Books (6) Python-DVD-Training (1) Python-Exercises (313) Python-Framework (1) Python-IDE (1) Python-Kivy-Framework (2) Python-Modules (1) Python-pdf (2) Python-pyQt (1) python-temp (3) Référencement (2) Script PHP (2) Security (6) SEO (1) Snipping Tool: Faq (1) Social Networks (1) Source Code (4) Statistics With SPSS (2) Surveillance Software (1) Travail à domicile (6) Tutoriels php en vidéos (2) Tutoriels-MySql (6) tutoriels-php (19) Utilitaires (1) VPS (1) Web Hosting (1) Webcam (1) Webmarketing (11) Western Union (1) Windows 10 (1) Windows 7 (4) Windows 7 Faq (2) Windows 8 (1) Windows Accessories (1) Windows Download (8) Windows Drivers (1) Windows Fonts (1) Windows Power Shell (2) Windows Registry (2) Windows Security (18) Windows Software (2) Windows Spyware (2) Windows utilities (3) Windows Virus (2) Windows Vista (3) Windows Wireless (1) Windows xp (1) Wordpress (1)

Sample text

Sample Text

Blogger Templates