Researchers have discovered a vulnerability in Android in active use in the wild, called Strandhogg, that lets attackers gather sensitive and private information from the victim without raising any flags. The vulnerability, discovered by app security firm Promon, lets attackers mimic any app on the phone. Many of the apps taking advantage of the vulnerability could be downloaded from the Google Play Store, compounding the problem. All Android versions are affected, and the permissions can be harvested on Android versions 6.0 onwards.”]