Google Deletes App on Pixel Phones–'Dangerous' New Spyware Warning
forbes.com
forbes.com
If an attacker has your phone and your password, it's game over anyway, who cares if some random app could allow MITM connections over HTTP.
Just as I saw this HN thread and started reading the article, I also noticed on my Pixel 8 phone had an Android 14 update (the "August 5th, 2024" update) which included this security patch: https://source.android.com/docs/security/bulletin/pixel/2024...
It includes 1 CVE patch for Pixel: CVE-2024-32927, which has a "high" severity and is an "Elevation of privilege" type. Android Bug ID: 312268456*.
When you look up the CVE is has no details, and the asterisk next to the Android Bug ID means that it's not publicly available[1]. This article just posted today but I wonder when the research and interviews for the article happened. Maybe the August patch includes the fix, or maybe it'll be the next one.
1. https://issuetracker.google.com/issues/312268456 - this is the android bug link, you can see in the network you get a 403 from one of the api calls, but for other bugs you don't
1. The app is installed by Verizon
2. The app is disabled by default ("The app is not enabled by default, but there might be multiple methods to enable it. The iVerify research team investigated one method requiring physical access")
The actual report:
https://iverify.io/blog/iverify-discovers-android-vulnerabil...
Their quote:
> Google is essentially giving CISOs the impossible choice of accepting insecure bloatware or banning Android entirely.
That doesn't sound like the case at all!
Not Google’s fault (beyond trusting carriers to not be incompetent :D)