Security News > 2024 > May > Microsoft warns of "Dirty Stream" attack impacting Android apps

Microsoft warns of "Dirty Stream" attack impacting Android apps
2024-05-02 16:02

Microsoft has highlighted a novel attack dubbed "Dirty Stream," which could allow malicious Android apps to overwrite files in another application's home directory, potentially leading to arbitrary code execution and secrets theft.

Dirty Stream allows malicious apps to send a file with a manipulated filename or path to another app using a custom intent.

This manipulation of the data stream between two Android apps turns a common OS-level function into a weaponized tool and can lead to unauthorized code execution, data theft, or other malicious outcomes.

Microsoft researcher Dimitrios Valsamaras noted that these incorrect implementations are unfortunately abundant, impacting apps installed over four billion times and offering a massive attack surface.

Two apps highlighted as vulnerable to Dirty Stream attacks in Microsoft's report are Xiaomi's File Manager application, which has over a billion installations, and WPS Office, which counts around 500 million installs.

Google rejected 2.28 million risky Android apps from Play store in 2023.


News URL

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-dirty-stream-attack-impacting-android-apps/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 699 800 4628 4391 3688 13507
Android 4 0 17 2 0 19