Security News > 2023 > April > CISA warns of Android bug exploited by Chinese app to spy on users
The U.S. Cybersecurity and Infrastructure Security Agency warned today of a high-severity Android vulnerability believed to have been exploited by a Chinese e-commerce app Pinduoduo as a zero-day to spy on its users.
"Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed," CISA explains.
On March 21, Google suspended the official shopping app of Chinese online retailer giant Pinduoduo from the Play Store after discovering malware in off-Play versions of the app, tagging it as a harmful app and warning users that it could allow "Unauthorized access" to their data or device.
Days later, Kaspersky researchers also revealed they had found versions of the app exploiting Android vulnerabilities for privilege escalation and installing additional modules designed to spy on users.
"Some versions of the Pinduoduo app contained malicious code, which exploited known Android vulnerabilities to escalate privileges, download and execute additional malicious modules, some of which also gained access to users' notifications and files," Kaspersky security researcher Igor Golovin told Bloomberg.
U.S. Federal Civilian Executive Branch Agencies agencies have until May 4th to secure their devices against the CVE-2023-20963 vulnerability added by CISA to its list of Known Exploited Vulnerabilities on Thursday.
News URL
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-24 | CVE-2023-20963 | Improper Certificate Validation vulnerability in Google Android In WorkSource, there is a possible parcel mismatch. | 7.8 |