August 15th, 2024

Google Pixel Phones Have Unpatched Flaw in Hidden Android App

A serious vulnerability in nearly all Google Pixel phones, linked to the "Showcase.apk" app, allows remote code execution. Google plans to remove it, but Palantir has stopped using Android devices.

Read original articleLink Icon
Google Pixel Phones Have Unpatched Flaw in Hidden Android App

A significant security vulnerability has been discovered in nearly all Google Pixel phones, linked to a hidden Android application called "Showcase.apk." This application, developed by Smith Micro for Verizon, has been present in every Android release for Pixel devices since September 2017. It operates at the system level, allowing remote code execution and software installation, which could potentially enable attackers to take control of the device. The vulnerability stems from the app's ability to download configuration files over an unencrypted HTTP connection, making it susceptible to hijacking. Although Google has acknowledged the issue and plans to remove the app in an upcoming update, the fix has not yet been implemented. The slow response from Google has led Palantir, a data analytics company, to discontinue the use of Android devices entirely, citing a loss of trust in the ecosystem. While the application is turned off by default, it still poses a risk if an attacker gains physical access to a device. iVerify, the security firm that uncovered the flaw, has expressed concerns about the implications of third-party software running with high privileges in the Android operating system. Google has stated that the app is not present in the newly announced Pixel 9 series and is notifying other Android manufacturers about the vulnerability.

- Nearly all Google Pixel phones are affected by a serious vulnerability in a hidden app.

- The "Showcase.apk" app allows remote code execution and could enable device takeover.

- Google plans to remove the app in an upcoming update but has not yet issued a fix.

- Palantir has decided to phase out Android devices due to concerns over security and trust.

- The vulnerability requires physical access to exploit, but it raises significant security concerns.

Related

Google Restricts RCS Messaging on Some Android Devices

Google Restricts RCS Messaging on Some Android Devices

Google restricts RCS messaging on certain Android devices like rooted ones. Users criticize the move, citing communication limitations. Google defends the action for spam prevention and security. Despite workarounds, affected users face challenges. This reflects Google's tighter control trend, akin to Apple. The competition between Android and iPhone, focusing on AI, may impact user preferences.

Loss of popular 2FA tool puts security-minded GrapheneOS in a paradox

Loss of popular 2FA tool puts security-minded GrapheneOS in a paradox

GrapheneOS faces challenges after Authy became incompatible, highlighting issues with Google's Play Integrity requirements. Ongoing discussions aim for compatibility, but legal action against Google may occur if exclusion continues.

Smartphone flaw allows hackers and governments to map your home

Smartphone flaw allows hackers and governments to map your home

A newly discovered smartphone vulnerability allows unauthorized tracking and surveillance through GPS data, raising significant privacy concerns as it does not require access to cameras or microphones.

Google patches Quick Share for Windows to shut malware hole

Google patches Quick Share for Windows to shut malware hole

Google patched multiple vulnerabilities in its Quick Share application for Windows, discovered by SafeBreach, which could allow remote code execution. Ten flaws were identified, including denial of service and authorization bypass.

Google Pixel phones sold with security vulnerability, report finds

Google Pixel phones sold with security vulnerability, report finds

A report by iVerify revealed a hidden vulnerability in Google Pixel phones since 2017, allowing potential surveillance. Google confirmed a fix will be released to remove the software.

Link Icon 3 comments
By @whopperplopper - 5 months
By @achristmascarl - 5 months
By @ramimac - 5 months
Press Release version in case anyone gets paywalled: https://www.prnewswire.com/news-releases/iverfiy-discovers-s...