Re: Washington Post says Google sold Android phones with hidden insecure feature

Liste des GroupesRevenir à cm android 
Sujet : Re: Washington Post says Google sold Android phones with hidden insecure feature
De : andrew (at) *nospam* spam.net (Andrew)
Groupes : comp.mobile.android
Date : 16. Aug 2024, 03:27:32
Autres entêtes
Organisation : BWH Usenet Archive (https://usenet.blueworldhosting.com)
Message-ID : <v9mdek$145d$1@nnrp.usenet.blueworldhosting.com>
References : 1 2
User-Agent : NewsTap/5.5 (iPad)
Jeff Layman wrote on Thu, 15 Aug 2024 22:31:17 +0100 :

I assume that showcase.apk was removed when grapheneOS was installed as
that is intended for use in Pixel phones.

You're correct that "showcase.apk" seems to be the culprit, according to
this news article about the Pixel flaw which shipped since 2017 apparently.
 *Researchers claim most Google Pixel phones shipped with exploitable bloatware since 2017*
 <https://www.engadget.com/mobile/smartphones/researchers-claim-most-google-pixel-phones-shipped-with-exploitable-bloatware-since-2017-185926564.html>

 "The issue relates to "Showcase.apk," a bit of software made for
  Verizon and used to put Pixel devices in demo mode while displayed
  in retail stores.

  The software downloads a configuration file over an unencrypted
  web connection, which - because of Showcase's deep access - might
  allow bad actors to perform remote code execution or remote
  package installation on the device.

  The especially troubling part of this discovery is that Showcase
  can't be uninstalled at the user level. And while it is not
  enabled by default, iVerify said there could be multiple ways
  to activate the software. iVerify alerted Google to the
  vulnerability in May; thus far there's no confirmed evidence
  it's been exploited in the wild.

  A Google spokesperson told Wired that Showcase is no longer being
  used by Verizon and that Google would have a software update to
  remove the software from all Pixel devices in the coming weeks.

  Additionally, the rep said Showcase is not present in the line
  of Google Pixel 9 devices announced during the Made by Google
  event this week."


Date Sujet#  Auteur
15 Aug 24 * Washington Post says Google sold Android phones with hidden insecure feature13Andrew
15 Aug 24 `* Re: Washington Post says Google sold Android phones with hidden insecure feature12Jeff Layman
16 Aug 24  `* Re: Washington Post says Google sold Android phones with hidden insecure feature11Andrew
16 Aug 24   +- Re: Washington Post says Google sold Android phones with hidden insecure feature1Bill Powell
16 Aug 24   `* Re: Washington Post says Google sold Android phones with hidden insecure feature9Jeff Layman
16 Aug 24    +* Re: Washington Post says Google sold Android phones with hidden insecure feature2Stan Brown
16 Aug 24    i`- Re: Washington Post says Google sold Android phones with hidden insecure feature1Jeff Layman
16 Aug 24    `* Re: Washington Post says Google sold Android phones with hidden insecure feature6Theo
16 Aug 24     `* Re: Washington Post says Google sold Android phones with hidden insecure feature5Jeff Layman
17 Aug 24      `* Re: Washington Post says Google sold Android phones with hidden insecure feature4Andrew
17 Aug 24       +* Re: Washington Post says Google sold Android phones with hidden insecure feature2Andy Burns
17 Aug 24       i`- Re: Washington Post says Google sold Android phones with hidden insecure feature1Andrew
18 Aug 24       `- Re: Washington Post says Google sold Android phones with hidden insecure feature1Jeff Layman

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal