Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Grindr, OkCupid, Viber million other Android apps are at a security risk: Check Point Research
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Grindr, OkCupid, Viber million other Android apps are at a security risk: Check Point Research

Grindr, OkCupid, Viber million other Android apps are at a security risk: Check Point Research

tech2 News Staff • December 8, 2020, 15:27:55 IST
Whatsapp Facebook Twitter

In September 2020, 13 percent of Google Play applications used this library, and 8 percent of those apps had a vulnerable version.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Grindr, OkCupid, Viber million other Android apps are at a security risk: Check Point Research

Viber, Grindr, OkCupid and several other Android apps have been found to be unguarded against the vulnerability CVE-2020-8913. This means, users of these apps, are facing a security risk. The vulnerability “allows Local-Code-Execution (LCE) within the scope of any application that has the vulnerable version of the Google Play Core Library. Code execution is an attacker’s ability to execute arbitrary commands or code,” according to security researchers at Check Point Research. The vulnerability was published back in August 2020. For the uninitiated, the ‘Play Core Library’ is the app’s runtime interface with the Google Play Store. Some of the actions that can be taken with Play Core include, triggering in-app updates, request in-app reviews, download additional language resources, among others. As per the researchers (via SandBlast Mobile), in September 2020, 13 percent of Google Play applications used this library, and 8 percent of those apps had a vulnerable version. For perspective, as of the third quarter of 2020, Google Play store had over 2.87 million apps on the platform. Google patched this vulnerability on 6 April 2020, however, developers are yet to push the patch to their application. Notably, when a vulnerability is on a server-end, the issue can be patched and applied completely to the affected apps, however, when it’s on the client-end, developers of all affected apps needs to get the latest version of the library and apply it to the app. [caption id=“attachment_6600001” align=“alignnone” width=“1280”] ![Google Play Store. Image: tech2](https://images.firstpost.com/wp-content/uploads/2019/05/Google-Play-Store-1280.jpg) Google Play Store. Image: tech2[/caption]

What is vulnerability CVE-2020-8913?

Before we understand the vulnerability, we need to understand a small part of how mobile applications work. Every mobile application sandbox has “verified” files from Google Play store and “non-verified” ones. The files that are downloaded from the official source, which in this case is Google Play, go into the verified folder, whereas files that are downloaded from other sources are sent to the non-verified folder. When a file is written to the verified folder, it interacts with the Google Play Core library which loads and executes it. Another feature is the ability to let other sources push files into the hosting application’s sandbox. Although, these files are pushed only into the non-verified folder, and it is not automatically handled by the library. “The vulnerability lies within the combination of the two features mentioned above, and also utilizes file traversal, a concept as old as the internet itself. When we combine popular applications that utilize the Google Play Core library, and the Local-Code-Execution vulnerability, we can clearly see the risks. If a malicious application exploits this vulnerability, it can gain code execution inside popular applications and have the same access as the vulnerable application,” according to researchers at Check Point. The vulnerability can cause high risks such as “injecting code into banking applications to grab credentials, while have SMS permissions to steal the Two-Factor Authentication (2FA) codes, Inject code into social media applications to spy on the victim, and use location access to track the device”, among others.

Tags
Android apps Google Play Viber Google Play Store Android apps OkCupid Grindr
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV