Quantcast
Channel: CodeSection,代码区,网络安全 - CodeSec
Viewing all articles
Browse latest Browse all 12749

AirDroid Beta 4.0.0.2 fixes major security issues, official rollout expected soo ...

$
0
0

AirDroid Beta 4.0.0.2 fixes major security issues, official rollout expected soo ...

A few days ago, independent securityfirm Zimperium released details about several major security flaws in the popular AirDroid application. In summary, attackers can easily intercept insecure requests to AirDroid's servers, as well as push malicious APKs to devices which appear as AirDroid add-on updates (which AirDroid then prompts the user to accept). Granted, the user has to be on an insecure Wi-Fi network for the attack to work, butit's still a major problem.

That alone is bad enough, but Zimperium informed AirDroid of the problem a whopping seven months ago. During that time, a major 4.0 update was released, which still had the same security issues. Once Zimperium disclosed the information publicly, AirDroid put out a blog post in broken English without any real explanation.

AirDroid did promise that a fix would be available within two weeks, and to their credit, the latest Beta version (4.0.0.2) does contain the fixes. The developers are waiting on Zimperium to verify that all the security issues are properly resolved before pushing it to all users.

I don't recommend using AirDroid (even after these issues are fixed), but if you absolutely have to, don't connectany Wi-Fi networks that you don't manage yourself until the fix is available. You can also sign up for the beta on Google Play here .


Viewing all articles
Browse latest Browse all 12749

Latest Images

Trending Articles





Latest Images