Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

12 Android Applications Have Security Holes, Users Should Update Immediately

Review Critical Security Vulnerability through the main facts, background, key details, and practical implications in this clear overview for readers.

Table of Contents

Mobile security company Oversecured has published an article revealing security vulnerabilities that have been discovered in Android applications and system components on Xiaomi phones, allowing thieves to access activities, Arbitrary services with system privileges, file theft…

Key Takeaways About Critical Security Vulnerability

  • Mobile security company Oversecured has published an article revealing security vulnerabilities that have been discovered in Android applications and system components on Xiaomi phones
  • 12 Android apps are affected by security vulnerabilities, including: Gallery (com.miui.gallery) GetApps (com.xiaomi.mipicks) Mi Video (com.miui.videoplayer) MIUI Bluetooth
  • Bluetooth, connected WiFi network and emergency contacts; shell command injection error affecting the System Tracing application.

12 Android apps are affected by security vulnerabilities, including:

  • Gallery (com.miui.gallery)
  • GetApps (com.xiaomi.mipicks)
  • Mi Video (com.miui.videoplayer)
  • MIUI Bluetooth (com.xiaomi.bluetooth)
  • Phone Services (com.android.phone)
  • Print Spooler (com.android.printspooler)
  • Security (com.miui.securitycenter)
  • Security Core Component (com.miui.securitycore)
  • Settings (com.android.settings)
  • ShareMe (com.xiaomi.midrop)
  • System Tracing (com.android.traceur), and
  • Xiaomi Cloud (com.miui.cloudservice)

12 Android applications have security holes, users should update immediately Picture 1 - Critical Security Vulnerability

Some notable bugs discovered in these 12 apps include bugs in the Settings app that could allow crooks to steal arbitrary files as well as leak device information, researchers said. Bluetooth, connected WiFi network and emergency contacts; shell command injection error affecting the System Tracing application.

The cause of the vulnerability is believed to be due to the Chinese phone manufacturer modifying legitimate components from the Android Open Source Project (AOSP) including Phone Services, Print Spooler, Settings and System Tracing.

In addition, researchers also discovered a memory corruption vulnerability, originating from an Android library called LiveEventBus that affects the GetApps application. Oversecured reported this vulnerability to project maintainers more than a year ago, but it has not been patched yet.

Oversecured said the issues have been reported to Xiaomi since April 25 and recommends that Xiaomi phone users update to the latest version to minimize potential threats.

Apple and The Citizen Lab have just discovered a serious security vulnerability, affecting a series of popular applications and millions of Internet users.

12 Android applications have security holes, users should update immediately Picture 2 - Critical Security Vulnerability

The discovered security vulnerability codenamed CVE-2023-4863 is related to heap buffer overflow in WebP due to programs and applications not managing memory well and allowing important system data to be overwritten.

If hackers successfully exploit the vulnerability, they can remotely take control of the system and launch larger-scale attacks.

This is a huge vulnerability because practically every software program or application that uses libwebp to display WebP images has problems.

The vulnerability affects a series of popular applications and OTT software such as Google Chrome, Mozilla Firefox, Microsoft Edge, Affinity, Gimp, Inkscape, LibreOffice, Thunderbird, ffmpeg, Honeyview, Telegram, Signal and 1Password.

In addition, the existence of WebP vulnerabilities also exists in many Android applications as well as cross-platform applications built with Flutter.

Google has confirmed the existence of the WebP vulnerability and has urgently released the Google Chrome 116 update to patch it.

Experts recommend that users who are using any of the applications mentioned in this article should update the software to the latest version immediately to keep their devices safer.

Apple's Security Architecture and Engineering (SEAR) team discovered and reported the WebP vulnerability in collaboration with The Citizen Lab on September 6, 2023.

FAQ

How do you choose the best Critical Security Vulnerability?

Mobile security company Oversecured has published an article revealing security vulnerabilities that have been discovered in Android applications and system components on Xiaomi phones, allowing thieves to access activities, Arbitrary services with system privileges, file theft...

What features matter most when comparing Critical Security Vulnerability?

12 Android apps are affected by security vulnerabilities, including: Gallery (com.miui.gallery) GetApps (com.xiaomi.mipicks) Mi Video (com.miui.videoplayer) MIUI Bluetooth (com.xiaomi.bluetooth) Phone Services (com.android.phone) Print Spooler (com.android.printspooler) Security (com.miui.securitycenter) Security Core Component

Who should consider the options in this guide?

Bluetooth, connected WiFi network and emergency contacts; shell command injection error affecting the System Tracing application.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.