Get All Access for $5/mo

Hackers May Be Able to Secretly Download Malicious Apps onto Nearly Half of All Android Phones The 'Android installer hijacking vulnerability' reportedly allows attackers to surreptitiously download apps to Android users without them knowing.

By Cale Guthrie Weissman

This story originally appeared on Business Insider

Dsimic | Wikimedia Commons

A researcher at Palo Alto Networks has discovered a frightening Android vulnerability that could allow hackers to steal data from unknowing users. Even scarier, it could affect nearly half of all current Android users.

Called the "Android installer hijacking vulnerability," the bug reportedly allows attackers to surreptitiously download apps to Android users without them knowing.

Here's how it works:

  • When an Android user installs an app, they are always directed to a permissions screen ensuring the user know what sort of requirements the app has.
  • This vulnerability, however, indicates that if a user downloads an app from a third-party app store or an app promotion (that is, not Google Play), Android doesn't make sure that the app being presented to the user in the permissions page is the actual app being downloaded.
  • This means that an attacker can "modify or replace the package in the background." That is, hackers can secretly change the files that you think you're downloading for other, more malicious ones. Think of it as an app bait and switch.

There are two ways for attacker to capitalize on this vulnerability. One, they can present to consumers a normal-looking app and then, once approved by the user, swap it for a piece of malware. Or, attackers can flat-out lie about the permissions the app requires, meaning app can look benign but actually gain all sorts of access to private phone data.

The fact that so many users are at risk highlights a real problem with Android. In short, Android operating systems are disturbingly fragmented. While the company has been working to fix its operating system fragmentation problem, more than half of the devices on the market use versions that are as many as three versions behind the latest. The most recent update, dubbed Lollipop, was released in November of 2014 and only 3.3% of all Android users currently run it.

Compare that with Apple, which claimed last fall that 94% of all iPhone users use a version of iOS that was released in the past year. With so many Android users spanning so many versions, it's difficult for Google to issue a clean fix to problems like these.

The Android installer hijacking vulnerability applies to Android 4.3 devices. It was first discovered in January of 2014 and the researchers informed Google, Samsung, and Amazon (all of which provide operating systems to which the vulnerability applies). Now, more than a year later, all of the vendors have installed patches to fix it, but earlier versions of Android are still at risk.

According to the most recent numbers, that represents 49.5% of the Android devices on the market.

The most obvious fix for Android users would be to update their software. If they are unable to do that, users should only download apps through Google Play, as those files are unable to be overwritten by attackers.

So if you're running an older version of Android, you better make sure you know what you're downloading.

Cale Guthrie Weissman covers cybersecurity/tech-politics for Business Insider.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Side Hustle

These Sisters Started a Side Hustle After a 'Light Bulb Moment' Led to a 'Versatile' Product. Now It's Done Over $45 Million in Sales.

Co-founders Lauren Stephens and Kaki McGrath, along with their mother Bonnie Dudley, turned everyday-wear brand Dudley Stephens into a multimillion-dollar success.

Growing a Business

Why Employee Accountability is the Holy Grail of Every Successful Business

There are huge benefits to creating a culture of accountability throughout your organization.

Business Ideas

63 Small Business Ideas to Start in 2024

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2024.

Business News

Melinda French Gates Announces Open Call for $250 Million Fund. Here's Who Can Apply.

The fund is part of French Gates's $1 billion philanthropic plan.

Side Hustle

New Research Reveals the Most Profitable Side Hustle — and You Could Make an Extra $15,000 a Year From Home

If you're ready to start a side hustle, it pays to consider which one will give you the greatest return.

Science & Technology

Here's the Key to Staying Ahead of the Competition, No Matter What Industry You're In

Here's how entrepreneurs can stand out in a competitive and saturated business marketplace by investing in original tech development.