A new unpatched #vulnerability — dubbed Strandhogg — in Android could let malicious apps take extensive control over your device & steal your login credentials.
Details: thehackernews.com/2019/12/strand…
Dozens of apps are already exploiting this flaw in the wild.
#Strandhogg task hijacking vulnerability can be exploited to display a fake user interface (UI) while tricking users into thinking they are using a legitimate app, making it easy for the malware to steal their credentials using spoofed login interfaces.
A malicious app can also escalate its capabilities significantly by tricking users into granting sensitive device permissions while posing as a legitimate app.
Read more: thehackernews.com/2019/12/strand…
#infosec #hacking #cybersecurity
➡️it's almost impossible to spot,
➡️it can hijack any app,
➡️it can request any device permission,
➡️it can be exploited without root,
➡️it works on all versions of #Android,
➡️it doesn't need any special permissions.