HomeNewsTechnologySecurity leak leaves Android phones from Samsung, LG and others vulnerable

Security leak leaves Android phones from Samsung, LG and others vulnerable

The leak resulted in the creation of malware apps that gain access to Android devices.

December 03, 2022 / 18:18 IST
Story continues below Advertisement
(Image Courtesy: Samsung)
(Image Courtesy: Samsung)

A security leak has left Android devices from manufacturers such as Samsung, LG and others, vulnerable to malware apps that steal user data and can gain access to their devices.

The reason why the leak is dangerous is that it contains platform certificates, which are used to verify apps and sign off on Android builds for these apps.

Story continues below Advertisement

In the wrong hands, these certificates can be potentially used to create apps that will be flagged as authentic by Android, even when they are not.

The Android signing certificates were leaked from multiple partner OEMs. Worse, the certificates are also used to determine whether the version of Android running on your phone is legitimate.
Unfortunately, the disclosure of the leak does not specify which OEM vendors were affected but as 9to5Google points out, it does show an example hash of malware files.

Using this, the publication managed to find out some of the organisations that have had certificates leaked. These include Samsung, LG and MediaTek among others.

Story continues below Advertisement