Discovered: Over 94% of popular Android apps are vulnerable
Anyone using a device running version 4.0 of Android - about 85 percent of Android systems in use today - is potentially vulnerable, claims a security company. Palo Alto Networks has presented a new research that highlights security risks in the internal storage used by applications on Google Android devices. But as Palo Alto Networks research reveals, an attacker may be able to steal sensitive information from most of the applications on an Android device using the Android Debug Bridge backup/restore function. Key findings include: -- Anyone using a device running version 4.0 of Android - about 85 percent of Android systems in use today - is potentially vulnerable -- To use ADB, an attacker would need physical access to the device, whether borrowing or stealing it from the user; an attacker could also take control of a system to which the device is connected via USB -- Over 94 percent of popular Android applications, including pre-installed email and browser applications, use the backup system, meaning users are vulnerable -- Many Android applications will store user passwords in plain text in Android Internal Storage, meaning almost all popular e-mail clients, FTP clients and SSH client applications are vulnerable -- Google has set the default for applications to allow back-ups; application developers are responsible for disabling the feature or otherwise restricting backups; however, the high percentage of applications that have not disabled or restricted backups suggests many developers are unaware of the risks Palo Alto Networks recommends Android users disable USB debugging when not needed, and application developers to protect Android users by setting android:allowBackup to false in each Android application’s AndroidManifest.xml file or restricting backups from including sensitive information using a BackupAgent.
Discover Related

SHAREit Vulnerability Could Have Left a Billion Android Users Exposed to Online Attacks

Android bug could infect almost a BILLION handsets through a MMS message
