Beware of Airdroid - over 20 million users exposed to security risks
A mobile security company called Zimperium has discovered a number of major security issues for Airdroid – a remote access management tool for Android with over 20 million downloads. Sand Studio – the product team behind Airdroid was informed by Zimperium about said vulnerabilities more than six months ago and promised to patch things up with the 4.0 release of the app which was introduced last month. The security company later found out that all of the issues still persisted on version 4.0, so it decided to make it's discoveries public today.
Zimperium's findings highlight how malicious parties can exploit the app's built-in functionalities and use them against users on the same network. Airdroid uses the same encrypted HTTP request to authorize the device and send usage statistics. The key to this encryption is hardcoded into the application, which means that everyone using it has the exact same key. With this key, attackers can intercept the authentication request and gain access to private account information, such as the e-mail address and password associated with the Airdroid account. Moreover, the hackers can also use a similar method to inject any malicious APK by prompting the app to notify the user of a required software update.
It is very unfortunate to see a developer putting profits before people and not focusing on security. While we all hope to see these issues fixed in the next update, it is advisable to stop or at least limit the use of this app until something is done to correct this.
source: Zimperium via Android Police
17 Comments
1. drifter77
Posts: 397; Member since: Jun 12, 2015
posted on Dec 02, 2016, 10:11 AM 5
2. emvxl
Posts: 139; Member since: Sep 29, 2009
posted on Dec 02, 2016, 10:33 AM 2
21. xondk
Posts: 1904; Member since: Mar 25, 2014
posted on Dec 03, 2016, 11:40 AM 0
3. Mxyzptlk unregistered
posted on Dec 02, 2016, 10:35 AM 4
13. Pabliell
Posts: 171; Member since: Mar 22, 2016
posted on Dec 02, 2016, 4:31 PM 5
4. Scott93274
Posts: 6020; Member since: Aug 06, 2013
posted on Dec 02, 2016, 11:17 AM 1
5. piyath
Posts: 2443; Member since: Mar 23, 2012
posted on Dec 02, 2016, 11:59 AM 1
6. joey_sfb
Posts: 6794; Member since: Mar 29, 2012
posted on Dec 02, 2016, 1:33 PM 4
7. gdawilson
Posts: 259; Member since: Jul 21, 2014
posted on Dec 02, 2016, 2:26 PM 4
11. sissy246
Posts: 6844; Member since: Mar 04, 2015
posted on Dec 02, 2016, 4:03 PM 1
12. sissy246
Posts: 6844; Member since: Mar 04, 2015
posted on Dec 02, 2016, 4:04 PM 0
8. tedkord
Posts: 16999; Member since: Jun 17, 2009
posted on Dec 02, 2016, 3:10 PM 3
9. Crispin_Gatieza
Posts: 3041; Member since: Jan 23, 2014
posted on Dec 02, 2016, 3:22 PM 1
10. kerginaldo17 unregistered
posted on Dec 02, 2016, 3:36 PM 0
17. vliang86
Posts: 337; Member since: Oct 05, 2015
posted on Dec 03, 2016, 1:07 AM 0
18. Pabliell
Posts: 171; Member since: Mar 22, 2016
posted on Dec 03, 2016, 1:14 AM 0
22. JunitoNH
Posts: 1946; Member since: Feb 15, 2012
posted on Dec 04, 2016, 8:57 PM 0
Comments Options
Report Post
Send a warning to post author
Send a warning to Selected user. The user has 0 warnings currently.
Ban user and delete all posts
Message to PhoneArena moderator (optional):