5/28/2023 0 Comments Trend micro android shareit 1b![]() Trend Micro’s team showed that they could install a malicious version of Twitter using this process. SHAREit stores downloaded games in an unprotected directory that all other Android apps have access to and write to. But it is possible the attack may work in other Android browsers. Trend Micro tried it and found that the attack did not work in Google Chrome because the browser detected suspicious behavior. But because the connection to SHAREit’s app store is not secure, it would be trivial for an attacker to stage a human-centered attack to inject malicious code into the connection and redirect the link so that your phone downloads malicious software.Ī malicious link may even be embedded in a website. The SHAREit app can download and install games directly from its own app store, outside the Google Play store. “They could also potentially lead to remote code execution (RCE).” “The vulnerabilities could be exploited to exploit a user’s sensitive data and execute arbitrary code with SHAREit permissions by using a malicious code or app,” the Trend Micro report said. But because SHAREit allows users to send Android app installers to each other, an attacker may find it easy to achieve. The shortcomings of SHAREit had to be exploited by a malicious app or junk code that was already installed on the Android device, the report states. The site is currently releasing the latest update on February 9 to improve the user experience. Trend Micro showed a screenshot of the app’s Google Play page, indicating that the last update was made on January 26, 2021. “We decided to disclose our research three months after we reported this, as many users may be affected by this attack because the attacker could steal sensitive data,” Trend Micro’s Echo Duan and Jesse Chang wrote in the report. ![]() SHAREit has not patched the errors despite being notified of them three months ago, Trend Micro said. In that case, you might want to disable or uninstall the Android version of SHAREit, which has more than a billion downloads according to Google Play.Ī report by security firm Trend Micro yesterday (February 15) said that the Android version (but not the iOS version) of SHAREit can be used to steal personal information or even used as a back door to take over phones. Have you ever used SHAREit? It’s an Android and iOS app that lets you share files with others who have the app installed on their phones, a kind of platform version of Apple’s AirDrop. ![]()
0 Comments
Leave a Reply. |