Blog

Major Security Issues Found With Popular Android App

Feb 27, 2021 | Blog

Do you use the app “ShareIt?”

It’s one of the most popular apps in the ecosystem, boasting more than a billion downloads from Google’s Play Store and nearly 2 billion downloads overall (including the Windows, iOS and MacOS ecosystems). On top of that, its original creator, Lenovo, preinstalled it on all Lenovo phones, which may have been the means by which you first encountered the app.

All that to say, it’s a hugely popular app and was in the top ten most frequently downloaded titles in 2019, so it has an enormous footprint.

Recently, Trend Micro conducted a security audit of the app, and their findings may make you rethink your use of it. According to the report the company published not long after their research was complete, they found several major security flaws that would allow for arbitrary code execution, which could result in the complete compromise of the target system.

Unfortunately, the security issues stem from a number of unfortunate design decisions that left the software incredibly vulnerable. One example of this is the fact that the app demands extensive permissions that gives it complete control over the entire storage system, access to all media files on the device, the ability to install or delete apps, create accounts, and more.

Adding to the problems with the app is the fact that its ‘private storage’ mechanism is anything but. An analysis of the code reveals that the ‘android:exported’ variable is set to False, but the AndroidGrantUriPermissions variable is set to True, which means that literally any third party entity can gain temporary read/write access to the user’s data.

Trend shared their findings with ShareIt’s development team more than three months ago, and to date, the developers have not patched any of them. So it’s as vulnerable today as it was when Trend first published their report. If you are a current user, you may want to consider uninstalling it until the company tightens up their security.

FBI Program Tasked with Infrastructure Security Compromised

FBI Program Tasked with Infrastructure Security Compromised

The FBI program tasked with ensuring critical infrastructure security has been compromised by hackers, who now offer access to the program's data on the dark web. The breach was initially disclosed by Brian Krebs of Krebs on Security, who claims that the data was for...

Streamline Your Business with the Latest Smart Home Technology

Streamline Your Business with the Latest Smart Home Technology

Are you a business owner looking to get the most out of your Google smart home devices? If so, you're in luck! Google has enabled its Nest products and Android OS with the initial rollout of the Matter smart home standard. This means that businesses now have the...

Data Breach at Sequoia One Exposes Sensitive Customer Information

Data Breach at Sequoia One Exposes Sensitive Customer Information

What do you do when your most personal information has been compromised? This is likely the question that customers of Sequoia One asked themselves earlier this month as they were informed that the company had been hacked. Sequoia One specializes in the management of...

Cisco Reports Critical IP Phone Vulnerability

Cisco Reports Critical IP Phone Vulnerability

As a business owner, it's important to stay informed about potential vulnerabilities that could impact your organization. Recently, Cisco reported a critical vulnerability, tracked as CVE-2022-20968, affecting its IP Phone 7800 and 8800 Series. This new vulnerability...

Google Chrome Releases Two New Features

Google Chrome Releases Two New Features

Google Chrome is one of the more commonly used web browsers. Over the years, though, Chrome has gained a reputation for utilizing a large portion of a computer's memory. This can be a problem if you're running other resource-intensive tasks and don't want to slow...

Get a Free Consultation

 

Fill out the form below to receive a free consultation and learn how we can make your technology worry-free!

 

Contact Information

  • 39301 Badger Street, Suite 500
    Palm Desert, CA 9221
  • (760) 333-8523
  • info@icn.tech