Security News > 2022 > December > Watch Out! These Android Keyboard Apps With 2 Million Installs Can be Hacked Remotely

Watch Out! These Android Keyboard Apps With 2 Million Installs Can be Hacked Remotely
2022-12-02 07:48

Multiple unpatched vulnerabilities have been discovered in three Android apps that allow a smartphone to be used as a remote keyboard and mouse.

The apps in question are Lazy Mouse, PC Keyboard, and Telepad, which have been cumulatively downloaded over two million times from the Google Play Store.

Telepad is no longer available through the app marketplace but can be downloaded from its website.

While these apps function by connecting to a server on a desktop and transmitting to it the mouse and keyboard events, the Synopsys Cybersecurity Research Center found as many as seven flaws related to weak or missing authentication, missing authorization, and insecure communication.

The Lazy Mouse server further suffers from a weak password policy and doesn't implement rate limiting, enabling remote unauthenticated attackers to trivially brute-force the PIN and execute rogue commands.

It's worth noting that none of the apps have received any updates for over two years, making it imperative that users remove the apps with immediate effect.


News URL

http://thehackernews.com/2022/12/watch-out-these-android-keyboard-apps.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19