Security News > 2020 > January > Google urged to tame privacy-killing Android bloatware

Google urged to tame privacy-killing Android bloatware
2020-01-13 11:18

These pre-installed apps can have privileged custom permissions that let them operate outside the Android security model.

This means permissions can be defined by the app - including access to the microphone, camera and location - without triggering the standard Android security prompts.

The letter references a joint US-Spanish study published last year which uncovered the surprising scale of the bloatware issue - of 140,000 pre-installed apps, only 9% were available on Google's Play Store, for example.

Some vendors are worse than others, and at least one, Samsung, uses its own additional Android apps and capabilities as a positive selling point, creating a platform-within-a-platform.

Pre-installed apps should have some update mechanism, preferably through Google Play and without a user account.


News URL

https://nakedsecurity.sophos.com/2020/01/13/google-urged-to-tame-privacy-killing-android-bloatware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 140 994 4863 2810 1621 10288
Android 4 0 17 2 0 19