Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Uncategorized

Attackers can exploit Android Certifi-gate to gain unrestricted device access

byCustoms Today Report
26/08/2015
in Uncategorized
Share on FacebookShare on Twitter

NEW YORK: Last night Google removed the app but it is still available in some third party app stores and under various names including EASY screen recorder. If you have installed a remote access program like this – remove it now if you can.

Certifi-gate is a vulnerability that allows applications to gain illegitimate privileged access rights that are typically used by remote support applications that are either pre-installed or personally installed on the device. Attackers can exploit Certifi-gate to gain unrestricted device access, allowing them to steal personal data, track device locations, turn on microphones to record conversations, and more.

You might also like

Pakistan to get $3b loan from Islamic Trade Financing Corporation

20/10/2024

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

10/09/2024

Certifi-gate was reported by iTWire on 7 August and it is pretty nasty stuff. The vulnerability cannot be easily patched – it may require a rewrite of the Android kernel.

Check Point published a Certifi-gate vulnerability scanner to check if an Android device had been infected. That led to the discovery of Recordable Activator and an infection rate of 15.84% of all devices scanned. For reasons unknown LG, Samsung and HTC devices had the respective highest infection rates – we assume it is due to market share.

Recordable Activator, an app developed by UK-based Invisibility Ltd., has had between 100,000 and 500,000 downloads on Google Play. It bypassed the Android permission model to use the TeamViewer’s plug-in to access system level resources and to record the device screen.

Recordable Activator demonstrates the following inherent issues related to Certifi-gate:

Unprivileged apps can leverage a vulnerability to take full control of a device without having to request permissions from Android to do so.

Even after TeamViewer fixed its official version, malicious parties can still abuse old versions of the plug-in to conduct malicious acts.

Mobile devices can be exploited even if a vulnerable plug-in was not pre-installed on a device.

Apps that can exploit these vulnerabilities can be found today on Google Play.

The only fix is for manufacturers to push updated ROMs to affected devices.

Well-known TeamViewer said that the way this app uses its plug-in is a violation of the code’s use and that it does not allow any third parties to use their code. It assures users that the updated (3 June) TeamViewer Quick Support for Android addresses the issue.

Other remote support apps (mRSTs) including Rsupport and CommuniTake Remote Care may also be vulnerable.

How to remove it

Check Point give details here but the bottom line is that if the TeamViewer plug-in was pre-installed (as many Android devices are) you will most likely not be able to uninstall it. In this case, contact your device manufacturer and ask for a fix.

 

 

 

 

Tags: Attackers can exploit Android Certifi-gate to gain unrestricted device access

Related Stories

Pakistan to get $3b loan from Islamic Trade Financing Corporation

byCT Report
20/10/2024

ISLAMABAD: Islamic Trade Financing Corporation (ITFC) to provide Pakistan with a $3 billion loan, according to an official statement released...

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

byCT Report
10/09/2024

LAHORE:  Regional Directorate of Customs Intelligence & Investigation has demonstrated exceptional performance in the first two months of the fiscal...

ICCI and CDA to join hands for tree plantation drive in Capital

byQaisar Mansoor
09/08/2023

ISLAMABAD: Islamabad Chamber of Commerce and Industry (ICCI) in collaboration with the Capital Development Authority (CDA) would jointly launch a...

Customs Officials Yawar Abbas & Tariq Mehmood kidnapped in Karachi

byCT Report
08/07/2023

KARACHI: Customs Intelligence Officer Yawar Abbas and Customs Preventive Officer Tariq Mehmood who were working against smuggling were kidnapped by...

Next Post

Have a look on Patent Images of Suzuki iM-4's Production Model

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.