Vulnerability in Baidu's Android SDK exposes 100 million Android devices
Security researchers from Trend Micro have discovered that a software development kit used by thousands of applications is leaving Android users at risk.
The Moplus SDK was created by Chinese firm Baidu and is susceptible to backdoor functionalities. It is believed that approximately 100 million Android devices users are affected.
"This SDK has backdoor routines such as pushing phishing pages, inserting arbitrary contacts, sending fake SMS, uploading local files to remote servers, and installing any applications to the Android devices without user’s authorization", the Trend Micro researchers explain. "The only requirement is for the device to be connected to the Internet first before any of these routines execute. Our findings also revealed that a malware is already leveraging Moplus SDK in the wild".