sábado, 9 de agosto de 2014

Security Flaw in Spotify for Android May Enable Phishing

Security Researchers Have Identified a Vulnerability in the Android Version of the Digital Music Service, Spotify, that Could Allow Attackers to Run Phishing Campaigns Against the User. According to Trend Micro, the Glitch is Present in Versions of the App Earlier that 1.1.1 and if Successfully Exploited, it Would Permit Taking Control of What is Displayed in the App’s Interface. Phishing is the Most Prevalent Form of Attack and in this Case, it May be Used by Cybercriminals to Collect Sensitive Information such as Passwords, Email Addresses and Even Financial Details, Considering that Spotify also Provides a Paid Service. Simon Huang, Mobile Security Engineer at Trend Micro, Says that, “the vulnerability affects a specific activity (com.spotify.mobile.android.ui.activity.TosTextActivity), which is designed to retrieve and show Spotify web pages on the app”.


As a Result, the Content of the Web Pages Can be Displayed in Other Apps Available in the Mobile Device. The Problem Goes Deeper than this, though, as there is the Possibility for an Activity to be Initiated by a Separate App, Process, or Thread without the Need of Additional Permissions. By Exploiting the Flaw, the Security Researcher was Able to Bring the Google Homepage in the Interface of the Spotify App. He Warns that Minimizing the Activity Can be Done without Restriction and if the Potential Victim Uses the “Back” Button to Stop Spotify, the Malicious Content Pops Up on the Screen. Spotify Responded to Trend Micro’s Notification and Released an Update for the App. All Users are Advised to Get the Latest Version, 1.1.2, as Soon as Possible in Order to Eliminate the Security Risk.



0 comentários:

Enviar um comentário