It also was already patched. Good write up though.
It also was already patched. Good write up though.
> Later articles were written about this bug, each examining the same exploit technique, coming to the conclusion that this vulnerability offered less abilities than the Master Key exploit, due to very narrow and unlikely requirements that the original signed application package must satisfy.
> In this article, I document different exploit techniques for this bug that do not have these limits; in fact, the second exploit described here provides much more capability than the Master Key exploit, allowing arbitrarily complex packages to take on the signatures from arbitrary signed packages. Finally, I look at the history of this bug in Android, showing when it was introduced.
Vendors don't prioritize updates because their customers don't understand enough to make this part of their purchasing decision, so there is little incentive for them to spend resources on it.
Minimizing this major problem doesn't help.
And - instead of saying 'think outside the box' - why not actually contribute some out of the box thinking?