A month ago, mobile security company Bluebox found a very serious security vulnerability, which affects almost 99% of Android devices in the past four years. This vulnerability allows hackers to inject malicious programs into any application without changing the encrypted signature certificate. This vulnerability is harmful. On Tuesday, Symantec, a famous security company, said it was the first to successfully fix the vulnerability signed by the Android app and identified four other infected apps on Wednesday, these applications are mainly spread through third-party application malls. Although security patches have been discovered, how to push to a large number of Android users remains a challenge for Google.
In general, the security authentication mechanism of Google Play mall is still relatively complete. However, due to the openness of the Android platform, many third-party application malls spread on the Internet without passing the authentication, therefore, it is still difficult to prevent malicious spread of these vulnerabilities on the existing Android platform.
Unfortunately, Google is not very easy to fix this vulnerability. Although each OEM has redesigned the firmware version and pushed it to the consumer, however, this is not an effective solution.