Vulnerabilities detected in some apps on Google Play
Computer scientists from Germany’s Leibniz University of Hannover and Philipps University of Marburg have found that apps downloaded by as many… Computer scientists from Germany’s Leibniz University of Hannover and Philipps University of Marburg have found that apps downloaded by as many as 185 million people have been putting to risk online banking and social networking credentials of users, along with their e-mail and instant-messaging contents. While researchers found no evidence indicating that any of the suspicious apps were developed by Google employees, they opine that Google engineers could surely work towards ensuring that Android apps implement the encryption more securely. The paper, presented at this week’s Computer and Communications Security conference, exposes yet another point of failure, which is poor implementation by app developers.” In his statement to Ars Technica, Jon Oberheide, CTO of mobile firm Duo Security added, “All things said, it’s generally good research that should make developers more aware of these basic security deficiencies that shouldn’t have made it through any respectable QA process,” “Needless to say, security isn’t top of mind of most mobile developers.” As part of their research, the scientists downloaded 13,500 free apps from Google Play and put them through a “static analysis”. Researchers found that 1,074 apps, or eight percent of the sample contained “SSL specific code that either accepts all certificates or all hostnames for a certificate and thus are potentially vulnerable to MITM attacks.” From the list of 1,074 potentially vulnerable apps, the researchers picked 100, and put them through manual audit.












Around 125 Android apps tracked user behaviour to run a million-dollar ad scam












Discover Related

Trump Signal: Why the messaging app isn’t to blame for the White House scandal.

What is Signal, the chat app US officials used to share attack plans, some of which were leaked?

IPL 2025: Cybercriminals exploit government sites to promote betting apps

Protectt.ai raises $8.7 mn in funding round led by Bessemer Venture Partners

1 Million Third-Party Android Devices Have a Secret Backdoor for Scammers

A Signal Update Fends Off a Phishing Technique Used in Russian Espionage

Beware Android users! Government warns against risk: How to protect your devices

A new crypto-stealing malware is targeting iPhones and Android smartphones

Your smartphone apps may have Malware: Follow these steps to check and stay safe

How Google protects you from dangerous apps: Top Play Protect features on Android

Google Play adds verified badge for VPNs, as NordVPN’s new trick bypasses blocks

Google to step up cyber defences after employee faced a devastating phishing attack

TikTok ban: VPN interest surges as Americans look for best ways to continue using app

I4C cites hoax threat mails in VPN app takedowns

iOS devices are easier target for hackers compared to Android: Report

Over half of APP scams last year ‘carried out by fraudsters using social media’

Protect yourself from cybercriminals, delete THESE apps before it's too late

FBI issues grave warning to all iPhone and Android users: stop sending texts

Android 15 users alert: Government flags high-risk security threats

Apple and Google face UK investigation into mobile browser dominance
