Android adware capability a vulnerability, claim boffins
Credit:
http://youtu.be/gLujaf0Y4-A
North Carolina State University researchers have revealed a vulnerability in Android that allows SMS messages to be sent from one app to another without going over the air, something they say could be used for SMS phishing attacks.
The Xuxian Jiang-led team is the same group that gave the world the Android click-jacking rootkit, a phone-call bugging vulnerability, and identified a dozen malicious apps on Google Play in 2011.
The team's latest announcement is characterised as a “WRITE_SMS capability leak”, because it can be exploited without an attacker having to request any permissions. The vulnerability is demonstrated in the video below.