A review in the organization of app permissions made by Google could allow malicious apps to silently gain further permissions on the victim’s device.
Google has recently made a significant change to the management process for permissions on Android devices, unfortunately security experts noticed that the change could advantage bad actors that intend to conduct attacks against the mobile platform.
- Hiding permissions behind the group names
- Auto-updating app process doesn’t trigger any alert is a new permission belonging to the same group is added.
“When an app updates, it may need to use additional capabilities or information controlled by permissions. If you have automatic updates enabled, you won’t need to review or accept these permissions as long as they are included in a permissions group you already accepted for that app.If the app needs access to an additional permissions group, you’ll be asked to accept the update, even if you’ve set an app to update automatically. If you prefer to review each update manually, you can change your update settings.” states Google.
- GPS Location and Network-based Location
- Read Phone State and Identity
- Automatically Start at Boot
- Modify/Delete SD Card Contents
- Read/Send SMS Messages
- Read/Modify Contacts
(Security Affairs – Google, app permissions)