• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

Flaw in Verizon Pixel’s firmware poses serious security threat

August 15, 2024
Share on FacebookShare on Twitter

Edgar Cervantes / Android Authority

TL;DR

  • Mobile security firm iVerify uncovered a significant vulnerability within the Showcase.apk package on Pixel devices sold through Verizon.
  • This package potentially exposes millions of Pixel users to man-in-the-middle attacks, spyware, and other threats.
  • The package is embedded in the firmware of Pixel devices sold through Verizon, so it cannot be uninstalled or removed by users.

Mobile security firm iVerify recently discovered a significant vulnerability that could potentially impact millions of Pixel devices globally. The said vulnerability was spotted within an Android application package on Pixel devices and can leave them susceptible to man-in-the-middle attacks, spyware installations, and more.

It’s worth noting that this package — Showcase.apk — runs at the system level and can fundamentally alter the way the device’s operating system functions. Since the package was installed over unsecured HTTP protocols, cybercriminals can potentially exploit this vulnerability and hack devices.

Unfortunately, since it’s a system-level app, the average user cannot uninstall or remove it from their device. This essentially leaves numerous Pixel owners at risk, but iVerify has notified Google about this security vulnerability and its associated risks, so it’s likely that the Mountain View tech giant will issue a patch to address this issue.

The package in question appears within the firmware of retail Pixel devices sold through Verizon. A substantial number of Pixel devices were found to have been shipped with it since September 2017. iVerify believes that the package was likely developed to provide customers with a demo mode, thereby enhancing sales of Pixel phones in Verizon stores. That said, the unintended security risks it presents are rather significant.

Regarding this issue, Rocky Cole, co-founder and Chief Operations Officer of iVerify, said, “While we don’t have evidence this vulnerability is being actively exploited, it nonetheless has serious implications for corporate environments, with millions of Android phones entering the workplace every day.”

The discovery of this package only underscores the need for thoughtful discussions on whether third-party apps should be included as part of the operating system. It also raises questions about the adequacy of quality assurance testing, especially when third-party apps are getting embedded within the firmware of retail devices. iVerify notes, however, that the application package was inactive by default on most devices it tested. For it to function, it would need to be manually enabled.

In our tests, we were able to locate the Showcase.apk package in the Pixel 8 Pro’s Verizon firmware for retail devices. As iVerify explains, the package is not enabled by default. However, the fact that you can manually enable it makes it a potential risk, both if you were to accidentally enable it yourself or if a cybercriminal were to find a way to enable it and hack into your device.

Got a tip? Talk to us! Email our staff at news@androidauthority.com. You can stay anonymous or get credit for the info, it’s your choice.

Next Post

Major Xbox Exclusive Is Reportedly Heading To PS5, Announcement Next Week

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Quantum computers need vastly fewer resources than thought to break vital encryption
  • Marathon review – ignore the noise, this game speaks for itself | Eurogamer
  • Nexus raises $4.3M to make enterprise AI agent deployment
  • My favorite ANC headphones for peaceful long flights are ALREADY $50 OFF
  • Apple Intelligence accidentally launches in China before regulatory approval

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously