Android Security & Malware – Telegram
Android Security & Malware
43.3K subscribers
127 photos
19 videos
7 files
2.69K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: mobilehackerofficial@gmail.com
Download Telegram
Buying new Android but already with pre-installed vulnerabilities

Android Firmware Vulnerabilities - November 2019
https://www.kryptowire.com/android-firmware-2019/
Analysis of use-after-free in Binder vulnerability - CVE-2019-2215

This exploit was used in-the-wild to install NSO group malware - Pegasus.
The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. If chained with a browser renderer exploit, this bug could fully compromise a device through a malicious website.
https://googleprojectzero.blogspot.com/2019/11/bad-binder-android-in-wild-exploit.html
Smartphone maker OnePlus discloses data breach

> says hackers accessed some OnePlus customer data through a vulnerability in its website
> hack happened last week
> OnePlus says it's opening a bug bounty program next month
Via @campuscodi
https://www.zdnet.com/google-amp/article/smartphone-maker-oneplus-discloses-data-breach/
XSS spoofing vulnerability found in Microsoft's Outlook for Android | CVE-2019-1460
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1460
HackerOne is looking for Mobile Security Engineer

//I would never thought I would post job offere in here, but this might help someone to move further in Mobile infosec field
https://jobs.lever.co/hackerone/316d0fbd-cf24-41be-a3e2-5180f62f3658
Compromise of Xiaomi Mi6 over WiFi to achieve RCE

Bug chaining:
MITM -> JavaScript Bridge (downloadAndInstallApk()) -> Contact Provider vulnerability (auto-start APK) -> RCE
https://labs.f-secure.com/advisories/xiaomi-wifi/
Malicious Android SDKs - oneAudience and MobiBurn - accessed personal data, such as email addresses and user names.

These SDKs were embedded in Twitter and Facebook Android apps
https://help.twitter.com/en/sdk-issue