the Google Play Store also suffered from a persistent code execution vulnerability. 8% of all Google Play Applications had been compromised by this. Google app, Android, 5 billion install. Had a bug that let a malicious app on phone gain extensive permissions on your device *wired.com
and its data into the cloud should be disabled Android:debuggable • Debugging features of the application should be disabled Android:installLocation • The application should be installed in the internal, more secure, memory Dangerous permissions • The application should not require dangerous permissions, as defined by Android, e.g. allow to make phone calls
or a other repackaged app acting on the adversary’s behalf that executes on the mobile device. • SQL databases; • Log files; • XML data stores or manifest files; • Binary data stores; • SD card Insecure Data Storage
traverse the mobile device’s carrier network and the internet. Threat agents might exploit vulnerabilities to intercept sensitive data while it’s traveling across the wire.
management. In mobile apps unlike in web apps, users are not always online. Hence mobile apps must be able to identify the user and maintain its identification along its session, when both online and offline.
the telephone Mitigation The application should refuse to run on a rooted device • On a rooted device, users can manipulate the code of the application.
code is obfuscated, it is much more difficult to understand the logic of the code • This makes it more difficult to manipulate the code or to find potential vulnerabilities • Decompile the code and assess its readability Mitigation