Home / news / AirDroid Android App is Vulnerable to Attack

AirDroid Android App is Vulnerable to Attack

If you’re an user, you may have heard of , a souped-up remote control app that lets you wirelessly connect to an phone or tablet. It’s impressively robust: you can respond to text messages directly from your , dismiss or answer an incoming call, silence notifications from certain apps, and even transfer files and photos simply by clicking and dragging. But it’s also frighteningly vulnerable to hacks: according to research firm Zimperium, a nasty security hole has left “tens of millions” of ’s users susceptible to data-stealing attackers.

At fault is the app’s weak method of encryption. In a blog post published Friday, Zimperium reported that AirDroid’s key — a digital passcode made up of a combination of numbers, letters, and characters — that it uses to obfuscate sensitive updates and data is both “static” and “easily detectable.” And while AirDroid uses the industry-standard HTTPS security protocol to handle most files, the app transfers crucial bits over unencrypted HTTP.

More: ‘Gooligan’ Android malware affects more than 1 million Google accounts

That opens the door for a reasonably skilled hacker to perform what’s known as a man-in-the-middle attack: using a third-party computer to impersonate AirDroid’s servers, deliver fraudulent app updates, and view sensitive information. In this manner, hackers could steal email addresses and passwords, surreptitiously install apps, or even replace the legitimate AirDroid application with a malicious replica.

“A malicious party on the same network as the victim can leverage this vulnerability to take control of their device,” Simone Margaritelli, Zimperium’s principle security researcher, told Ars Techica. “Moreover, the attacker will be able to see the user’s sensitive information … As soon as the update, or fake update, is installed the software automatically launches the updated [Android app file] without ever verifying who built it.”

Zimperium disclosed the vulnerability to AirDroid in May, but it remains present in the newest major release of AirDroid — version 4 — launched in mid-November. A subsequent patch, version 4.0.0.1, doesn’t appear to have addressed the flaw. And San Studios, the development team behind AirDroid, has yet to respond to Zimperium’s accusations.

In a statement published to the official AirDroid blog, Sand Studio said it hoped to have a fix ready within two weeks.

More: “Hummingbad,” a new Android malware, has infected more than 10 million devices

If you’re an active AirDroid user, your options are relatively few.

Android limits the extent to which malicious apps can modify your phone’s files, but AirDroid has more access than most. It can make app purchases, and can access contacts, text messages, device location, camera, microphone, photos, Wi-Fi connection data, device ID, and call information. And a malicious update posing as a legitimate one could request additional permissions.

A private network, or VPN, is a potential — but imperfect — solution. VPNs add a layer of security to unencrypted networks, providing a measure of protection from attackers. Ars Technica notes, though, there’s no guarantee a hacker won’t work around it by employing a captive portal — the sort of web page that hotels and airlines use to collect payment and registration information — to kick a VPN user to a compromised connection.

Until the problem’s patched, you’re best off using AirDroid only on wireless networks that you know and trust. If you rely on public Wi-Fi, though, you’re safest disabling or uninstalling AirDroid until a patch is in place.

Also watch:

(function($) {
var $el = $(‘.h-related-video’).last();

DTEvent.getEventPromise(‘dt:relatedvideo:init’).then(function() {
DTEvent.getEventPromise(‘dt:stickyvideo:init’).then(function() {
var video_data = DT.RelatedVideo.getNext() || {};

if (!video_data[‘attachment_id’] || !video_data[‘content_id’]) {
return;
}

if (video_data[‘title’]) {
$el.find(‘.h-title’).append(‘ ‘ + video_data.title);
}

$el.removeClass(‘is-hidden’);

new DTVideos.Jwplayer(
‘dt-content-footer-video-5841ceecb4282’,
{
autostart: false,
mute: false,
},
{
attachment_id: video_data.attachment_id,
content_id: video_data.content_id,
discovery: true,
}
);
});
});
}(jQuery));

Check Also

Kobo's New Aura H2O Can Survive a Dunk in the Pool

Why it matters to you If you’re in the market for an affordable, durable new …

Leave a Reply

Your email address will not be published. Required fields are marked *