Doctor Web has discovered a bug in the UC Browser mobile browser for devices running Android hidden ability to download and run unverified code.

UC Browser is very popular, with over 500 million downloads from the Google Play Store. The program requires an operating system. Android 4.0 or higher.
Doctor Web experts discovered that the browser has a hidden feature for downloading auxiliary components from the internet. The application is capable of downloading additional software modules bypassing servers Google Play, which violates Google's policies. This feature could theoretically be exploited by attackers to distribute malicious code.

"While the application has not been known to distribute Trojans or unwanted programs, its ability to download and run new and unverified modules poses a potential threat. There is no guarantee that attackers won't gain access to the browser developer's servers and use its built-in update function to infect hundreds of millions of users." Android-devices,” warns Doctor Web.
The said add-on download feature has been present in UC Browser since at least 2016. It can be used to organize Man-in-the-Middle attacks by intercepting requests and spoofing the C&C address. ServerMore information about the problem can be found here.
Source: 3dnews.ru
