• Android: Pre-installed carrier security findings

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Android: Pre-installed carrier security findings

    Author
    Topic
    #2579368

    Relevance: Smartphone Security
    Author: Ryan Johnson
    Date: 11th August 2023
    Article: quokka

    Did your android smartphone come furnished with carrier apps, some that may not be removed?

    Just came across an article on the security of carrier software on various android devices where the researchers have provided a list of smartphones they have examined and found to have vulnerabilities within 21 prepaid Android carrier devices in the US…

    …In the instances of insecure pre-loaded software on the prepaid Android carrier devices we discovered, we demonstrate that a third-party app that requests 0 to 1 permissions in its manifest file, can achieve a range of capabilities without proper authorization by leveraging insecure co-located, pre-installed software…

    Devices from the following US carriers have been examined:

    AT&T
    Bost Mobile
    T-Mobile
    Tracfone
    Verizon
    Visible

    ..So at this point, you may be wondering how to protect the personal data on your device. A good place to start is by educating yourself on the threats and risks associated with mobile devices. In general, it is critical to keep all of your software up to date as each update may contain security fixes that patch known software vulnerabilities…

    Good advice, and the article finishes with a direction to Q-Scout, a free Android and iOS app that checks whether your device has been impacted by vulnerabilities.

    Googleplay

    iOS App Store

    Keep that mobile device and your data safe..
    (Disclaimer, I have no association with any of the aforementioned parties, etc..)

    Windows - commercial by definition and now function...
    1 user thanked author for this post.
    Viewing 0 reply threads
    Author
    Replies
    • #2580099

      Q-Scout

      Tested the app on my iPhone.
      Not worth it. False/Fake alerts, like the app alerting VLC connecting to shady servers, data sent to mail.ru…apps can access my social media (I don’t have any)…

    Viewing 0 reply threads
    Reply To: Android: Pre-installed carrier security findings

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: