Close Menu
  • Home
  • Technology
  • Devices
  • Business
  • Science
  • Gadgets
  • Startups
Ayaksız
  • Home
  • Technology

    Lucid and Bolt Plan 25,000 Robotaxis for Europe

    Eylül 18, 2026

    AMD Gives PC Builders More Choice With New Ryzen 5 Desktop Chips

    Eylül 11, 2026

    Apple Expands Device Protection With a $49.99 Family Plan

    Eylül 11, 2026

    Snapdragon 8 Elite Extreme Gen 6 Reportedly Beats MediaTek’s Next Flagship Chipset

    Eylül 11, 2026

    Pinterest CFO Julia Donnelly to Step Down in October

    Ağustos 30, 2026
  • Devices

    iQOO 16 Design and Colour Options Unveiled With Major Camera Upgrade Confirmed

    Eylül 11, 2026

    Lava Bold N4 Pro 5G India Launch Date, Design and Key Specs Confirmed

    Eylül 11, 2026

    Xiaomi 18 Pro Max Geekbench Listing Reveals Key Specifications

    Eylül 10, 2026

    Samsung Galaxy Tab S12 Ultra, Tab S12+ Design Leaks in New Renders

    Eylül 10, 2026

    Vivo X500 Series Designs Revealed Ahead of September Launch

    Eylül 10, 2026
  • Business

    Google Pixel 11 Pro Leaked Renders Indicate It Might Sport Thinner Bezels Than the Pixel 10 Pro

    Mart 30, 2026

    Motorola Edge 70 Debuts With Snapdragon 7 Gen 4, Ultra-Slim 5.99mm Body

    Kasım 5, 2025

    Samsung Galaxy S26 Series Could See Price Increase Amid Rising Component Costs: Report

    Kasım 4, 2025

    Amazon’s AWS Partners with NBA to Power New AI Basketball Platform

    Ekim 4, 2025

    Billionaire-Backed Bitcoin Firm OranjeBTC to List on Brazil’s B3 Exchange

    Ekim 4, 2025
  • Science

    SpaceX’s $1.75 Trillion Valuation Raises Questions Ahead of IPO

    Nisan 11, 2026

    US Moves to Ease Satellite Power Limits, Boosting Space Broadband

    Nisan 10, 2026

    iPhone 17 Pro Max NASA Approves iPhone 17 Pro Max for Use on Artemis 2 Deep Space Mission

    Nisan 6, 2026

    Spain’s First Private 5G Satellite Mission

    Şubat 17, 2026

    Eutelsat Signs Launch Deal With MaiaSpace for LEO Satellites

    Ocak 17, 2026
  • Gadgets

    Vivo Buds Debut in India With Up to 50-Hour Battery Life

    Eylül 10, 2026

    Moto Buds 2 Fusion India Launch Date Confirmed, Features Teased

    Eylül 10, 2026

    Sennheiser Unveils Accentum Clip Earbuds With Up to 36 Hours of Total Battery Life

    Temmuz 2, 2026

    Nothing Ear 3a and CMF Buds Neo Appear in Regulatory Filings, Hinting at Upcoming Launch

    Haziran 2, 2026

    OnePlus Watch 4 Leak Hints at Launch With Snapdragon W5 and OxygenOS Watch 8

    Nisan 22, 2026
  • Startups

    Glean Reaches $7.2 Billion Valuation Amid AI Investment Surge

    Haziran 15, 2025

    How I Built a $2 Billion Super App: The Journey of Grab’s Anthony Tan and ’20-Hour’ Workdays

    Ekim 7, 2024

    Tupperware Files for Bankruptcy as Demand Declines

    Eylül 18, 2024

    Wildfire Detection Device Wins UK James Dyson Award

    Eylül 12, 2024

    Japan and Tokyo Governments Eye $4.7 Billion Valuation for Tokyo Metro in Upcoming IPO

    Ağustos 19, 2024
Ayaksız
Anasayfa » Blog » Microsoft Discovers Significant Security Flaw ‘Dirty Stream’ in Android Apps with Billions of Downloads
Tech

Microsoft Discovers Significant Security Flaw ‘Dirty Stream’ in Android Apps with Billions of Downloads

By ayaksızHaziran 17, 2024Yorum yapılmamış3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Microsoft Attributes Vulnerability to Improper Implementation of Android’s Content Provider System

Microsoft recently uncovered a significant security vulnerability present in multiple Android apps, which could potentially allow unauthorized access to apps and sensitive data on the device. Interestingly, this security flaw doesn’t stem from the Android system codes themselves but rather from developers improperly utilizing a specific system, creating loopholes that are susceptible to exploitation. It’s worth noting that Microsoft has informed Google about this flaw, and Google has taken steps to notify the Android app developer community about the issue.

According to a post on its Security Blog, the Microsoft Threat Intelligence team stated, “Microsoft discovered a path traversal-affiliated vulnerability pattern in multiple popular Android applications that could enable a malicious application to overwrite files in the vulnerable application’s home directory.” The researchers noted that several apps on the Google Play Store, with a combined total of more than four billion installations, were affected by this vulnerability.

This vulnerability arises from incorrect usage of Android’s content provider system, which is designed to secure data exchange between different apps on a device. This system includes various security measures such as data isolation, URI permissions, and path validation to prevent unauthorized access by apps or any malicious actors trying to exploit the apps. However, improper implementation affects a component called custom intents, which facilitate two-way communication between different apps. When this vulnerability exists, apps may bypass security measures, allowing other apps or hackers controlling them to access sensitive data stored within them.

Microsoft discovered a major security vulnerability in multiple Android apps last week that could be exploited to gain unauthorised access to apps and sensitive data on the device. Interestingly, this security flaw does not come from the system codes, but an improper usage of a particular system by developers that can lead to loopholes prone to exploitation. Notably, the flaw has been highlighted to Google, and the tech giant has taken steps to make the Android app developer community aware of the issue.

 

 

In a post on its Security Blog, the Microsoft Threat Intelligence team stated, “Microsoft discovered a path traversal-affiliated vulnerability pattern in multiple popular Android applications that could enable a malicious application to overwrite files in the vulnerable application’s home directory.” The researchers also highlighted that the vulnerability was spotted in several apps in the Google Play Store that had a combined total of more than four billion installations.

This vulnerability emerges when a developer incorrectly uses Android’s content provider system, which is designed to secure data exchange between different apps on a device. This includes data isolation, URI permissions, path validation and other security measures to stop unauthorised access by the apps or anyone else breaking into the app. However, improper implementation of the system affects a component called custom intents. These are the messaging objects that conduct two-way communication between different apps. When this vulnerability exists the apps can ignore the security measures and let other apps (or hackers controlling them) access sensitive data stored in them.

Google has also taken cognisance of the issue and published a post on its Android Developers blog. The company has highlighted the common errors and ways to fix them. It is expected that developers of affected apps will be fixing the issues in the coming days and release a fix. While end users cannot do much to avoid this vulnerability, it is recommended that they remain proactive in updating the apps on their devices and avoid downloading apps from third-party sources for a while.
Android Apps cyber security Google Play Store Malware Microsoft
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
ayaksız
  • Website

Related Posts

Lucid and Bolt Plan 25,000 Robotaxis for Europe

Eylül 18, 2026

AMD Gives PC Builders More Choice With New Ryzen 5 Desktop Chips

Eylül 11, 2026

Apple Expands Device Protection With a $49.99 Family Plan

Eylül 11, 2026
Add A Comment

Comments are closed.

Recent Posts
  • Lucid and Bolt Plan 25,000 Robotaxis for Europe
  • AMD Gives PC Builders More Choice With New Ryzen 5 Desktop Chips
  • Apple Expands Device Protection With a $49.99 Family Plan
  • Snapdragon 8 Elite Extreme Gen 6 Reportedly Beats MediaTek’s Next Flagship Chipset
  • iQOO 16 Design and Colour Options Unveiled With Major Camera Upgrade Confirmed
Tags
AI AI Chips AI Infrastructure Amazon Android Apple Artificial Intelligence Bitcoin ChatGPT China Cryptocurrency Cybersecurity data centers DeepSeek Donald Trump Electric Vehicles Elon Musk Ether Generative AI Google Huawei India Investment Iphone Meta Microsoft NASA National Security Nvidia OnePlus OpenAI Oppo Realme Samsung semiconductor industry Social media Sony SpaceX Technology Tesla Tether TikTok Vivo WhatsApp Xiaomi
Ayaksız
Instagram
© 2026 Ayaksız.

Type above and press Enter to search. Press Esc to cancel.