Security researchers have warned about a widespread vulnerability in Android devices that could see attackers sneakily modify or entirely replace seemingly benign apps with malware. The vulnerability can be successfully exploited on Android 2.3-4.0.4, 4.1.X, and 4.2.x which means 49.5% of Android devices currently in use are at risk. Fortunately, apps downloaded from the official Google Play Store are not at risk as they are downloaded into a protected space which cannot be overwritten by attackers.”]
Source: https://grahamcluley.com/android-users-at-risk-of-malware-via-installer-hijacking-vulnerability/

