Moneycontrol PRO
HomeNewsTechnologySecurity leak leaves Android phones from Samsung, LG and others vulnerable

Security leak leaves Android phones from Samsung, LG and others vulnerable

The leak resulted in the creation of malware apps that gain access to Android devices.

December 03, 2022 / 18:18 IST
(Image Courtesy: Samsung)

A security leak has left Android devices from manufacturers such as Samsung, LG and others, vulnerable to malware apps that steal user data and can gain access to their devices.

The reason why the leak is dangerous is that it contains platform certificates, which are used to verify apps and sign off on Android builds for these apps.

In the wrong hands, these certificates can be potentially used to create apps that will be flagged as authentic by Android, even when they are not.

The Android signing certificates were leaked from multiple partner OEMs. Worse, the certificates are also used to determine whether the version of Android running on your phone is legitimate.


Unfortunately, the disclosure of the leak does not specify which OEM vendors were affected but as 9to5Google points out, it does show an example hash of malware files.

Using this, the publication managed to find out some of the organisations that have had certificates leaked. These include Samsung, LG and MediaTek among others.

For now, Google is urging OEM partners to swap out the leaked certificates, so they can no longer be used.

Google reported that the leak happened in May 2022, and stated that the users are protected against this vulnerability through Google Play Protect and "mitigation measures" implemented by OEM partners.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Dec 3, 2022 06:18 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347