Auteur Sujet: [Trend]Janus Android App Signature Bypass Allows Attackers to Modify Legitimate Apps  (Lu 2733 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Janus Android App Signature Bypass Allows Attackers to Modify Legitimate Apps

Android’s regular security update for December 2017 included a fix for a serious vulnerability that could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to gain access to the affected device (indirectly). First found by researchers in July, this vulnerability (designated as CVE-2017-13156, and also called the Janus vulnerability) affects versions of Android from 5.1.1 to 8.0; approximately 74% of all Android devices have these versions installed.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


Janus Android App Signature Bypass Allows Attackers to Modify Legitimate Apps


Source: Janus Android App Signature Bypass Allows Attackers to Modify Legitimate Apps

Tags: