The vulnerability in Android mentioned earlier on Habré, which "...
allows attackers to turn any application into a Trojan " has been removed and the patch has been handed over to manufacturers.
The vulnerability discovered by the Bluebox Labs team was that the hacker had the opportunity to modify the application's APK file without changing the corresponding cryptographic signature. It was alleged that more than 900 million devices operating under different versions of Android, starting with 1.6, are potentially exposed to the problem.
Android team public relations manager Gina Scigliano (
Gina Scigliano ) told ZDNet observers that her company is not going to make an official statement about the problems in Android, but simply confirmed that the corresponding patch has already been sent to OEMs (Samsung, in particular ), which are already engaged in its application to end devices.
Also, Gina expectedly reported that there was nothing to worry about:
We have no evidence that someone exploited a vulnerability in Google Play or other app stores. Google Play is scanned for problems, the Verify Apps mechanism provides protection for Android users who download the app, bypassing the official store.
OriginalWe’ve not seen any app. Verify Apps for Google Play for Android users.
')
[
Source ]