Leaked Android certificates and signing malware

Google researcher reports that certificates signing keys of Samsung, LG, Mediatek and many other OEMs were leaked.

android code

Lukasz Siewierski, member of Google's Android Security Team, he published in the Android Partner Vulnerability Initiative (AVPI) issue tracker its certificate keys s leaked and used to sign malware.

The post is a list of certificates, but if you run each of them through the APKMirror or the website VirusTotal of Google well-known names will appear: h SamsungThe LG and Mediatek are the big hits on the list of leaked certificates, along with some smaller OEMs like Revoview and tablet maker Szroco 's Onn.

The Senior Technical Mishaal Rahman, also posted excellent information for the specific leak on Twitter.

As he explains, having an app that has the same UID as Android's system isn't quite root access, but it's close and allows that app to escape any sandboxing restrictions that exist for system apps.

These apps can communicate directly with (or, in the case of malware, spy on) other apps on your phone. Imagine a malicious version of the to get an idea.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
android, google, certificates, malware

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).