Connect with us

Hi, what are you looking for?

Tech & Science

StrandHogg Android vulnerability update (Includes interview)

With the vulnerability affecting all Android devices, known as StrandHogg, the new critical threat was identified during December 2019. The vulnerability allows real-life malware to pose as legitimate apps with users unaware they’re being targeted, granting hackers access to all kinds of personal information, including SMS, photos, geolocations, contacts and phone logs.

According to the BBC, the vulnerability is used to fool users into thinking they are using a legitimate app but are actually clicking on an overlay created by the attackers.

Promon, who discovered the flaw in Google’s Android software, has shared an update, in which StrandHogg is described as a ‘Critical Severity Vulnerability’ – the highest severity rating. According to Promon: “This is the highest severity rating, meaning that a fix is urgently required.”

In the meantime, Google has said it has taken action to close the loophole and was keen to find out more about its origins.

Inn terms of what the issue means for users of Android devices, Sam Bakken, Senior Product Marketing Manager, OneSpan, provides an update for Digital Journal. OneSpan develop security and anti-fraud solutions for more than half of the world’s top 100 banks and thousands of other enterprises.

Bakken says: “It’s great to see Google acknowledging the danger of the StrandHogg Android flaw by labeling it a ‘Critical Severity Vulnerability’ and planning to issue a CVE.”

However, he is less impressed with the technology giant in terms of time, noting: “It’s unfortunate that it took four years to do so because it gave attackers ample time to use the StrandHogg vulnerability to steal Android users’ mobile banking credentials and access one-time-passwords sent via SMS.”

However Bakken is pleased to see the action is being taken: “Luckily, app developers can take action to protect their apps and consumers. Mobile app security technology like app shielding can protect against the StrandHogg vulnerability and other similar security issues that Google still has not fixed in Android.”

Avatar photo
Written By

Dr. Tim Sandle is Digital Journal's Editor-at-Large for science news. Tim specializes in science, technology, environmental, business, and health journalism. He is additionally a practising microbiologist; and an author. He is also interested in history, politics and current affairs.

You may also like:

Tech & Science

The groundbreaking initiative aims to provide job training and confidence to people with autism.

Entertainment

Steve Carell stars in the title role of "Uncle Vanya" in a new Broadway play ay Lincoln Center.

Entertainment

Actors Jeremy Jordan and Eva Noblezada star in the new musical "The Great Gatsby" on Broadway.

World

US Secretary of State Antony Blinken (L) is paying his second visit to China in less than a year - Copyright POOL/AFP Mark SchiefelbeinShaun...