The presentation discusses the vulnerabilities found in pre-installed and third-party file transfer apps on Android devices, which can lead to file leaking and tampering, privacy leaks, arbitrary file downloads, and even remote code execution. The researchers present the related vulnerabilities' details and exploit techniques, as well as practical mitigations. They aim to raise awareness among users and mobile vendors to pay more attention to this serious situation and fix it better and sooner.
- Nearby sharing apps on Android devices have serious vulnerabilities that can be exploited by attackers to steal files and compromise privacy
- Most top mobile vendors' pre-installed nearby sharing apps have algorithm and design flaws that can lead to file leaking and tampering, privacy leaks, arbitrary file downloads, and even remote code execution
- Third-party file sharing apps are even worse about security and are used by over 1 billion users
- The researchers present the related vulnerabilities' details and exploit techniques, as well as practical mitigations
- They are working with most of the top vendors to mitigate these vulnerabilities
The researchers used reverse engineering to analyze pre-installed and third-party file transfer apps on Android devices and found many vulnerabilities that can be exploited by attackers. They presented the vulnerabilities' details and exploit techniques, as well as practical mitigations. They also emphasized the importance of raising awareness among users and mobile vendors to fix these vulnerabilities better and sooner.