HTC user data exposed to web apps

Powered by SC Magazine
 

HTCLoggers.apk binded to TCP.

Mobile phone manufacturer HTC is investigating a reported vulnerability that gives any internet-connected app access to users' personal information.

The flaw, affecting several of its Android smartphone models, was discovered and reported by researcher Trevor Eckhart on 24 September.

Eckhart published the vulnerability after he received no response for five days, the AndroidPolice blog reported.

The bug stems from a recently added program, HTCLoggers.apk, which logs large amounts of information from the phones, according to Eckhart.

The program enables any app that requests permission to connect to the web to easily access data that has been logged.

This information includes user accounts, email addresses, GPS locations, SMS data, phone numbers and system logs.

The flaw affects HTC Android phones, including the EVO 3D, EVO 4G and Thunderbolt, among others, Eckhart said.

HTCLoggers allows any application with internet access to bypass access permissions for information including GPS location data and system log. Applications could connect to the internet and obtain the information it had gathered.

HTC said it would issue a software fix.

“HTC takes our customers' security very seriously, and we are working to investigate this claim as quickly as possible,” the company said in a statement.

"We will provide an update as soon as we're able to determine the accuracy of the claim and what steps, if any, need to be taken.”

Eckhart created a proof-of-concept application that can be run on vulnerable phones to demonstrate the bug.

He also created a YouTube video to show how the flaw could be exploited on a stock EVO 3D.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


HTC user data exposed to web apps
 
 
 
Top Stories
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
Immigration breached Privacy Act with data leak
Pilgrim slams "copy and paste" of asylum seeker data.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 841

Vote