silversurfer
Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
- Aug 17, 2014
- 9,652
Android apps with over 250 million downloads are still susceptible to a severe vulnerability in a Google library that was patched in August 2020.
In August, mobile app security company Oversecured discovered a vulnerability in the Google Play Core Library that allowed malicious applications to execute code in legitimate apps.
Researchers from Check Point Research have discovered that there are still apps with millions of installs using the vulnerable library over three months later.
"Since the publication of this vulnerability, we started monitoring vulnerable applications [...] " Check Point Research stated in their report.
Below is a list of some of the vulnerable applications discovered by Check Point. As you can see, all of these apps have at least 1 million downloads, with one as high as 100 million downloads.
App Name Version Download Count Aloha 2.23.0 1,000,000 Walla! Sports 1.8.3.1 100,000 XRecorder 1.4.0.3 100,000,000 Moovit 5.56.0.459 50,000,000 Hamal 2.2.2.1 1,000,000 IndiaMART 12.7.4 10,000,000 Edge 45.09.4.5083 10,000,000 Grindr 6.32.0 10,000,000 Yango Pro (Taximeter) 9.56 5,000,000 PowerDirector 7.5.0 50,000,000 OkCupid 47.0.0 10,000,000 Teams 40.10.1.274 1,000,000 Bumble 5.195.1 10,000,000

Android apps with 200 million installs vulnerable to security bug
Android apps with over 250 million downloads are still susceptible to a severe vulnerability in a Google library that was patched in August 2020.