Riley Hassell: Android flaw can disable, corrupt AV tools
L33tdawg: Riley's spilling more details at HITBSecConf2011 - Malaysia in just 2 weeks... Online registration is open till the 7th and further details of his presentation is here.
Riley Hassell, founder of Privateer Labs, a boutique security firm, told ZDNet Asia during a phone briefing Friday that this issue afflicts a "popular component" of the Android OS, which he declined to disclose as he is scheduled to speak to Google regarding the vulnerability.
According to him, hackers can create malicious apps and publish them on the Android Market as "trusted apps" since the marketplace does not check on the software before they are made available to the masses. Once such apps are installed by a user, they can disable antivirus software on the device by exploiting the component's vulnerability. In some cases, the antivirus software can be corrupted and be utilized as a malicious app for cybercriminals to steal the mobile owner's personal information, he said.
Hassell stressed that this is "definitely an Android problem", adding he had tested the vulnerability on "top-end" mobile antivirus software. That said, the research is not complete and more details will be disclosed to ZDNet Asia in the following weeks and via the Hack in the Box conference in Kuala Lumpur next month.