FacebookInstagramTwitterContact

 

These Highly Effective Alternatives To Toxic Medication Help Beat Depression           >>           Study Highlights The Vast Medicinal Properties Of The Popular Spice Saffron           >>           Physically Healthy 28-Year-Old Dutch Woman With Autism And Depression Given Approval To End Her Life Through Assisted Suicide           >>           Haunted Holiday Home Horror As Tourists Left Screaming By 'Ghosts' Moving Picture Frames           >>           'A Reckless Kid Ruined My Car Door - His Mum's Response Left Me Gobsmacked'           >>           Olivia Wilde And Jason Sudeikis' 10-Year-Old Son Otis Is All Grown Up In Rare Photo           >>           Why Anne Hathaway Says Kissing Actors In Chemistry Tests Was So "Gross"           >>           NASA's Voyager 1 Spacecraft Finally Phones Home After 5 Months Of No Contact           >>           Meta opens Quest OS to third parties, including ASUS and Lenovo           >>           Newsletter service Ghost will support the fediverse protocol ActivityPub           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Android Exploit Adds Secret, Thieving Layers To Your Phone


Jan Persiel/Flickr

 


 May 26th, 2017  |  09:40 AM  |   2296 views

ENGADGET

 

Google is aware of the issue.

 

Researchers from UC Santa Barbara and Georgia Tech have discovered a fresh class of Android attacks, called Cloak and Dagger, that can operate secretly on a phone, allowing hackers to log keystrokes, install software and otherwise control a device without alerting its owner. Cloak and Dagger exploits take advantage of the Android UI, and they require just two permissions to get rolling: SYSTEM ALERT WINDOW ("draw on top") and BIND ACCESSIBILITY SERVICE ("a11y").

 

This concerns researchers because Android automatically grants the draw-on-top permission for any app downloaded from the Play Store, and once a hacker is in, it's possible to trick someone into granting the a11y permission. A Cloak and Dagger-enabled app hides a layer of malicious activity under seemingly harmless visuals, luring users to click on unseen buttons and keystroke loggers.

 

"To make things worse, we noticed that the accessibility app can inject the events, unlock the phone, and interact with any other app while the phone screen remains off," the researchers write. "That is, an attacker can perform a series of malicious operations with the screen completely off and, at the end, it can lock the phone back, leaving the user completely in the dark."

 

 

 

Google is aware of the exploit.

 

"We've been in close touch with the researchers and, as always, we appreciate their efforts to help keep our users safer," a spokesperson says. "We have updated Google Play Protect -- our security services on all Android devices with Google Play -- to detect and prevent the installation of these apps. Prior to this report, we had already built new security protections into Android O that will further strengthen our protection from these issues, moving forward."

 

One of the researchers, Yanick Fratantonio, tells TechCrunch the recent updates to Android O might address Cloak and Dagger, and the team will test it out and update its website accordingly. For now, he says, don't download random apps and keep an eye on those permissions.

 


 

Source:
courtesy of ENGADGET

by Jessica Conditt, @JessConditt

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Tens Of Thousands Evacuated From Massive China Floods

 2024-04-23 00:01:47

Wind Farm Misses Deadline For Electricity Sale Scheme

 2024-04-23 00:24:53