The security flaw was reported to Android by the teamof security researchers (Ryan Olson, Huagang Xie, Claud Xiao, Colt Blackmore, and Taylor Ettema) from the Palo Alto network. Palo Alto previously worked with Google, Amazon and Samsung to report vulnerabilities and then issue their patches. The company discovered this vulnerability in January last year and reported it to Android security team, Amazon and Samsung.
This vulnerability is so severe that the users passwords and sensitive information are not safe. They can be hijacked through the infected app which was installed through the third-party. Around 49.5 percent Android users were infected by this app before it was patched by the Android (on its latest versions only).
mobile ads libraries that do not rely on Google Play store would be
likely to save the promoted apps in unprotected storage, example ‘sdcard’.
Like the example we show with Amazon appstore app, the unprotected
storage in sdcard may allow attackers to replace the promoted apps with