City
Epaper

Bugs found in backend systems of top 5,000 free Android apps

By IANS | Published: August 13, 2019 2:08 PM

Cybersecurity researchers have identified more than 1,600 vulnerabilities in the support ecosystem behind the top 5,000 free apps available in the Google Play Store.

Open in App

While the researchers from Georgia Institute of Technology and The Ohio State University studied only applications in the Google Play Store, applications designed for iOS may share the same backend systems.

The vulnerabilities were found in the backend systems that feed content and advertising to smartphone applications through a network of Cloud-based servers.

The vulnerabilities, affecting multiple app categories, could allow hackers to break into databases that include personal information - and perhaps into users' mobile devices, said the study scheduled to be presented at the 2019 USENIX Security Symposium in the US on Thursday.

"These vulnerabilities affect the servers that are in the cloud, and once an attacker gets on the server, there are many ways they can attack," said Brendan Saltaformaggio, Assistant Professor in Georgia Tech's School of Electrical and Computer Engineering.

The researchers were still investigating whether attackers could get into individual mobile devices connected to vulnerable servers.

"It's a whole new question whether or not they can jump from the server to a user's device, but our preliminary research on that is very concerning," Saltaformaggio added.

In their study, the researchers discovered 983 instances of known vulnerabilities and another 655 instances of zero-day vulnerabilities spanning across the software layers - operating systems, software services, communications modules and web apps - of the Cloud-based systems supporting the apps.

To help developers improve the security of their mobile apps, the researchers have created an automated system called SkyWalker to vet the Cloud servers and software library systems.

SkyWalker can examine the security of the servers supporting mobile applications, which are often operated by Cloud hosting services rather than individual app developers.

( With inputs from IANS )

Tags: SkywalkerusGeorgia Institute Of TechnologyThe Ohio State University
Open in App

Related Stories

MaharashtraGanesh Chaturthi 2024: Pen's Ganpati Bappa Goes Global as Fifth Batch of 5,000 Idols Shipped to Canada and America

InternationalUS Announces $275 Million in New Security Assistance for Ukraine, Including Ammunitions and Artillery Rounds

InternationalUS Secretary of State Announces New Visa Restrictions on Georgia for Undermining Democracy

HealthH5N1 Bird Flu Human Cases in US & Australia Cause Concern: Know the Reason

International"New India is...": Pak UN envoy brings up "targeted assassinations" in homeland, elsewhere

कारोबार Realted Stories

BusinessSannverse Railtech's long-term IPO plans to emerge as a Titan in India's Railtech infrastructure and Rail Technology

BusinessNxcar Leads Auto Fintech Innovation as the First Company to Introduce Loans for Peer-to-Peer Used Car Transactions

BusinessBook authored by Prolific Law Educator MJ Sir ranked number 1 within 48 hours of its release

BusinessAfter Paytm, Adani Group denies media reports of buying stake in fintech company

BusinessMuthoot Pappachan Group announces Shah Rukh Khan as new brand ambassador