Security News > 2023 > April > CISA warns of Android bug exploited by Chinese app to spy on users

CISA warns of Android bug exploited by Chinese app to spy on users
2023-04-16 14:08

The U.S. Cybersecurity and Infrastructure Security Agency warned today of a high-severity Android vulnerability believed to have been exploited by a Chinese e-commerce app Pinduoduo as a zero-day to spy on its users.

"Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed," CISA explains.

On March 21, Google suspended the official shopping app of Chinese online retailer giant Pinduoduo from the Play Store after discovering malware in off-Play versions of the app, tagging it as a harmful app and warning users that it could allow "Unauthorized access" to their data or device.

Days later, Kaspersky researchers also revealed they had found versions of the app exploiting Android vulnerabilities for privilege escalation and installing additional modules designed to spy on users.

"Some versions of the Pinduoduo app contained malicious code, which exploited known Android vulnerabilities to escalate privileges, download and execute additional malicious modules, some of which also gained access to users' notifications and files," Kaspersky security researcher Igor Golovin told Bloomberg.

U.S. Federal Civilian Executive Branch Agencies agencies have until May 4th to secure their devices against the CVE-2023-20963 vulnerability added by CISA to its list of Known Exploited Vulnerabilities on Thursday.


News URL

https://www.bleepingcomputer.com/news/security/cisa-warns-of-android-bug-exploited-by-chinese-app-to-spy-on-users/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-03-24 CVE-2023-20963 Improper Certificate Validation vulnerability in Google Android
In WorkSource, there is a possible parcel mismatch.
local
low complexity
google CWE-295
7.8