• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

SHAREit vulnerability could affect over a billion Android devices days before US ban

February 16, 2021
Share on FacebookShare on Twitter

The popular SHAREit app isn’t just set to be banned in the US in the next three days; it was also apparently vulnerable to a (slightly convoluted) attack. The technical details are a bit of a slog, but in short, the app could indirectly allow for the execution of arbitrary code remotely, read or overwrite the app’s local files, or even allow for third-party APKs to be installed. Developers of the app, which claims over a billion installs at the Play Store, were notified of the vulnerability three months ago, but according to Trend Micro, they haven’t done anything to address it.

You can click through the source link down at the bottom for all the technical details, but the short version is that any app can hand SHAREit a bit of code to trigger further arbitrary execution of code by the app, also allowing it to read and write from the app’s siloed storage. On top of that, SHAREit can be instructed to download an APK from a handful of hard-coded URLs and install it. Thankfully, Chrome is smart enough to detect and mitigate this kind of attack hand-off when used as a vector to trigger it, but other avenues are also possible, and it’s also subject to a sort of man-in-the-middle attack via storage. It’s all pretty convoluted, but this can be combined in a way that could leave customer’s devices vulnerable — though, admittedly, it sounds like users would have to participate in specific actions to make it effective.

Play Store listing details for SHAREit.

SHAREit was originally part of Lenovo, and the app may even be pre-installed on some Lenovo Android devices, furthering the potential spread of this vulnerability. It claims over one billion downloads to date on its Play Store listing, and a “Lite” version of the app was released in 2019.

Security researchers claim they reported these vulnerabilities to the developers behind the app three months ago. The information is only now being divulged to raise awareness since the company behind the app seemingly wasn’t interested in addressing the issue during that time.

SHAREit likely isn’t too popular in the US, but the app is well-known in some markets, allowing customers to quickly and simply share files with one another locally. It also has some of its own content like videos, music, and gif/wallpaper discovery, as many apps targeting developing markets cram in to encourage use.

Although we have a new administration here in the US, to our knowledge, the app is still set to be banned in just a few days following a decision from outgoing president Trump, though the order itself seems to have been removed. Notably, it wasn’t included in the list of reversed orders on January 20th. The app has also been banned in India. It’s pretty unlikely we’ll get a response, but we have reached out to confirm if the order will still be enforced in the US this Friday.

Next Post

15 states sue NHTSA over delayed hike in automaker emissions penalties

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • AdultFriendFinder profiles: 3 tips to sort legit from fake
  • Match vs. eharmony: Which serious dating app is better?
  • Project Songbird Review – A Symphony of Horror | COGconnected
  • 50+ places to get birthday freebies, including Sephora, Cheesecake Factory, and more
  • The next Android update may finally undo some of Google’s worst decisions

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously