Search Articles

Search Results: AndroidSecurity

Accrescent 0.27.0 Overhauls Android App Store with Atomic Updates, Background Installs

Accrescent 0.27.0 Overhauls Android App Store with Atomic Updates, Background Installs

Accrescent's most significant release rebuilds its core architecture for reliability, introducing atomic metadata updates, background installations, and comprehensive device compatibility checks. The privacy-focused Android app store also adds granular error reporting, asset module support, and revamped UI while resolving longstanding installer issues.
Pixel by Pixel: New Pixnapping Attack Steals 2FA Codes from Android Devices in Seconds

Pixel by Pixel: New Pixnapping Attack Steals 2FA Codes from Android Devices in Seconds

Academic researchers have unveiled 'Pixnapping,' a novel Android attack enabling malicious apps to covertly harvest sensitive screen data like 2FA codes and chat messages within 30 seconds, bypassing traditional permissions. Exploiting a GPU timing side channel similar to the prior GPU.zip web attack, Pixnapping reconstructs displayed information pixel-by-pixel. While Google issued partial mitigations, a modified version remains effective, exposing fundamental limitations in Android's inter-app data isolation.
Google Reaffirms Android Sideloading Survival Amidst New Verification Rules

Google Reaffirms Android Sideloading Survival Amidst New Verification Rules

Google explicitly states sideloading 'absolutely not' going away on Android despite new mandatory developer verification requirements. The policy shift mandates digital signatures for sideloaded apps to combat malware while sparking debates about developer privacy and app control. Security gains come with potential trade-offs for niche tools and unfiltered app distribution.
Unpatched OxygenOS Flaw Exposes OnePlus Devices to Silent SMS Data Theft

Unpatched OxygenOS Flaw Exposes OnePlus Devices to Silent SMS Data Theft

A critical vulnerability in OnePlus's Android implementation allows malicious apps to access SMS content without permissions or user interaction. Despite seven disclosure attempts by Rapid7 over four months, OnePlus failed to respond, leaving millions of devices exposed. The unpatched flaw enables attackers to reconstruct private messages via SQL injection attacks.
Android's Developer Verification Threatens Offline Sideloading, SDK Reveals

Android's Developer Verification Threatens Offline Sideloading, SDK Reveals

New evidence in the Android SDK suggests Google's mandatory developer verification system could block app installations even from verified sources without an active internet connection. This raises concerns for users in low-connectivity scenarios, highlighting a potential pitfall in the upcoming security overhaul.