Google fixed four dozen vulnerabilities this week, including a bug dubbed Janus that could be exploited by attackers to inject malicious code into Android apps without affecting an apps signature verification certificates. The vulnerability was reported to Google by security researchers from mobile security firm GuardSquare this summer and has been fixed now as part of the December Android Security Bulletin. The Janus vulnerability stems from the possibility to add extra bytes of code to APK files and to DEX files. Android devices older than Nougat (Android) devices that support the APK signature scheme are affected by the vulnerability.”]
Source: http://securityaffairs.co/wordpress/66513/hacking/janus-vulnerability-android.html

