CERT-In warns against Android vulnerability that lets the attacker hijack any app on an infected device

India’s cybersecurity agency, the Computer Emergency Response Team (CERT-In), has recently issued a warning on its website against a new security vulnerability that lets an attacker hijack any app on an Android device.

“An Elevation of Privilege vulnerability named “StrandHogg 2.0” had been reported in the Google Android due to confused deputy flaw in the “start activities()” in the “ActivityStartController.java” which allow the attacker to hijack any app on an infected device,” read the CERT-In advisory.

The vulnerability can be used to install a malicious app on an Android device that hides behind legitimate apps. This malware then lets attackers hijack any app on the infected device.

Read more

You may also like

Comments are closed.