A dangerous feature in UC Browser threatens hundreds of millions of Android users

Doctor Web has detected a hidden capability in the UC Browser mobile browser for Android devices that allows downloading and executing unverified code.

A dangerous feature in UC Browser threatens hundreds of millions of Android users

The UC Browser is very popular, with over 500 million downloads from the Google Play Store. The application requires an Android operating system version of 4.0 or higher.

Experts at Doctor Web have found that the browser has a hidden capability to download auxiliary components from the Internet. The application can download additional software modules bypassing servers Google Play, which violates Google's policies. This feature could theoretically be exploited by attackers to spread malicious code.

A dangerous feature in UC Browser threatens hundreds of millions of Android users

Despite the fact that the application has not been detected distributing trojans or unwanted programs, its ability to download and execute new and unverified modules poses a potential threat. There is no guarantee that attackers will not gain access to the browser developer's servers and use the built-in update function to infect hundreds of millions of Android devices,” warns Doctor Web.

The described add-on download feature has been present in UC Browser since at least 2016. It can be used to organize Man in the Middle attacks by intercepting requests and replacing the address of the controlling server. More details about the issue can be found here. 




Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster