Millions of Android devices could be hacked exploiting a plugin that comes pre-installed on your Android devices by the manufacturers. Device manufacturers pre-install ” plugin onto their phones that are intended to help users, such as RSupport or TeamViewer. Remote support tools often have root level access to Android devices, even if your device is not rooted. An attacker can exploit mRATs to exfiltrate sensitive information from devices such as location, contacts, photos, screen capture, and even recordings of nearby sounds.
Source: https://thehackernews.com/2015/08/certifi-gate-android-vulnerability.html

