Tech Trends

Microsoft Has Uncovered Security Risks in Popular Android Apps

Highlights

  • Microsoft reveals serious vulnerabilities in widely used Android apps.
  • Vulnerabilities allow attackers to hijack app functions and access sensitive data.
  • Xiaomi’s File Manager and WPS Office identified and fixed the issues.
  • Users advised to update apps and monitor accounts for unusual activity.

Microsoft has identified some widely used Android apps that could put users at serious risk.

In a recent blog post, the company revealed it found a vulnerability pattern affecting multiple Android apps that allows cyber criminals to completely take over how an app functions.

What’s more, attackers could even gain access to users’ accounts and sensitive personal information through this flaw.

The vulnerability centres around apps not properly isolating themselves, which lets malicious apps trick other apps into overwriting important files.

After discovering this issue, Microsoft informed the affected app developers so they could fix the problem.

Two Apps Mentioned as Malicious

Microsoft Has Uncovered Security Risks in Popular Android Apps

Two of the mentioned apps were Xiaomi’s File Manager, installed over a billion times, and WPS Office, downloaded over 500 million times.

The issues with these apps were resolved in February, but users should ensure their apps are fully updated.

For apps like Xiaomi’s File Manager that connect to remote file shares, the impact extends beyond just the user’s phone.

As such, users of this app should reset their credentials and watch for any unusual behaviour.

Microsoft is concerned this vulnerability may exist in other apps they didn’t examine.

They hope highlighting this issue pushes publishers to check their apps and avoid introducing similar flaws going forward.

To protect themselves, Microsoft advises Android users to always run the latest app versions downloaded from trusted sources only.

More Recent Flaws Found in Chinese Keyboards

Microsoft reveals serious vulnerabilities in widely used Android apps

More recently, researchers at the Citizen Lab in Toronto, Canada, have discovered significant security vulnerabilities in cloud-based keyboard apps designed for typing Chinese characters using the pinyin system.

These vulnerabilities could potentially allow malicious actors to access the keystrokes of over a billion users.

The study examined apps from nine major manufacturers including Baidu, Honor, Huawei, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi, finding that eight of these transmitted user keystrokes to remote servers.

The primary concern stems from the cloud-based prediction features of these apps, which claim to enhance the speed of typing in Chinese.

This functionality involves sending keystrokes to cloud servers for processing, inadvertently facilitating a potential breach where these inputs could be intercepted.

FAQs

What did Microsoft discover about Android apps?

Microsoft identified a vulnerability pattern in several popular Android apps that could allow cybercriminals to take control of app functionalities and access user accounts and personal information.

This discovery was shared in a recent blog post by Microsoft.

Which apps were mentioned as having vulnerabilities?

Microsoft specifically mentioned two apps with vulnerabilities: Xiaomi’s File Manager, which has been installed over a billion times, and WPS Office, which has seen over 500 million downloads.

Both apps have since been updated to address these security issues.

What steps did Microsoft take after discovering the vulnerabilities?

After identifying the vulnerabilities, Microsoft notified the developers of the affected apps to enable them to patch the flaws.

This proactive measure helped mitigate potential risks associated with the vulnerabilities.

What should users of the affected apps do?

Users of apps like Xiaomi’s File Manager are advised to update their apps to the latest version to patch the vulnerabilities.

Additionally, they should reset their credentials and remain vigilant for any signs of unusual activity on their devices.

Also Read: Kaspersky Report Highlights Over 600 Million Malware Downloads from Google Play Store

Also Read: Supreme Court Tech Committee Finds Malware, Pegasus Spyware Suspected

Also Read: SpyNote Malware Targets Android Users By Recording Your Calls, Taking Screenshots

Share
Published by
Team My Mobile

Recent Posts

Huawei MatePad 11.5, MatePad SE 11 Full Specs Revealed Ahead of India Launch via Flipkart Microsite

Highlights Huawei MatePad 11.5 and MatePad SE 11 details are revealed via Flipkart listing. MatePad…

10 hours ago

Vivo X300s Spotted on Geekbench With Dimensity 9500 chipset and Up To 16GB RAM; Launching on March 30 Alongside X300 Ultra

Highlights Vivo has officially confirmed the X300s will launch in China on March 30 alongside…

14 hours ago

OnePlus 15T Launch Set for March 24 with Dual 50MP Cameras, LUMO Imaging System and 7,500mAh Battery

Highlights OnePlus 15T will launch in China on March 24 at 7 PM Beijing Time…

16 hours ago

Xiaomi Launches New-Generation SU7 Electric Sedan in China with Up to 902km Range and 3.08s Acceleration

Highlights Xiaomi unveiled the new-generation SU7 electric sedan in China. The sedan retains luxury C-segment…

17 hours ago

Samsung Galaxy S25 Ultra Gets Price Revision in India With Up to ₹10,000 Cut on Select Variants

Highlights Samsung Galaxy S25 Ultra gets a major price cut in India effective March 20,…

19 hours ago

Oppo K14 5G Goes on Sale in India Today with 7,000mAh Battery – Price, Specs, Offers

Highlights Oppo K14 5G goes on sale in India from March 20 via Flipkart and…

20 hours ago

This website uses cookies.