Experts at Palo Alto Networks discovered the Installer Hijacking vulnerability that exposes half of Android users to attack via Installation Vulnerability. By exploiting the flaw, an attacker can gain unlimited permissions on compromised smartphone and data it manages, including users credentials and sensitive data. The company has released a vulnerability scanner app in the Google Play store which it has open sourced on Github. The vulnerability only affects mobile apps downloaded from third-party app stores, meanwhile applications published on Google Play official store are safe because use a sandboxing mechanism for file downloads.”]
Source: https://securityaffairs.co/wordpress/35270/hacking/android-installer-hijacking-vulnerability.html

