Millions of Google Pixel Phones Include an App to Surveil & Control the Software [Android News Byte]

preview_player
Показать описание
A new security report shows Google has refused to patch this security vulnerability.

~~~~~

Mentioned Links
~~~~

Video Description
~~~~~~
Good afternoon, everyone, and welcome to another edition of the Android News Byte.
Today, I want to highlight a new report from a cybersecurity company called iVerify.

Their team completed an endpoint detection and response scan, aka an EDR scan, which detected an insecure device within Palantir Technologies.

Upon further investigation, their team learned this application was developed for Verizon for use with in-store demos.

A spokesperson at Google confirmed this was used for Verizon's in-store demo devices, but did not comment on how or why it made its way onto devices being sold to the public.

They continued by saying Google has seen no evidence of any active exploitation using this vulnerability.

However, I find it interesting that iVerify first reported this issue to Google back in early May
but they chose to not publicly disclose this issue at all
nor have they release a software update to remove this application from devices sold to the public

but now that this report has gone public, the company has confirmed Google would remove the app from all Pixel devices "in the coming weeks."

personally, I find this troubling to learn about considering Google Pixel devices are supposed to be clean from bloatware like this
I'm not so much worried about the presence of the application itself
since it is disabled by default. meaning a malicious actor would need to either trick you into enabling it. . .or have physical access to the device

however, I don't like the idea that Google ignored the report for months
before then deciding to release an update that would remove the app from affected devices

it's not like it would have taken very many resources for this to have been included in the June security patch

with that said, I was unable to find this apk file on my Pixel 8 that was sold via the Google Play Store
but you can use a package name application to search for the APK file if you are worried about it being on your device

the apk file has been pre-installed, and included in OTA updates issued by google. so sadly, you will not be able to remove it yourself without root access

#android #androidnews

but the good news is that google has said they will fix this in an update soon

Step by Step Tutorial
~~~~~~~~~~~~~~~~~
1. Intro [00:00]
2.

As an Amazon associate, I may earn a commission on sales from the links below.

The Gear I Use
~~~~~~~~~~~~~~~~~
Рекомендации по теме
Комментарии
Автор

Just a thought, but, I wonder what outcry there would be if such a package was found on a Chinese phone ..
If it happens to an American device or company, it's worth a video with a couple of hundreds of views and an article on a blog that no one knows.
I find this strange, to be honest.

Spicysauced
Автор

the mark of excellence is definitely palantir and peter thiel. definitely nothing sus going on here.

kirv
Автор

This is total bullshit. You can't even show us a phone that HAS THIS EXPLOIT.

ARDiesel