IBM X-Force Application Security Research Team has discovered a vulnerability in the Dropbox SDK for Android (CVE-2014-8889) The vulnerability allows attackers to connect applications on mobile devices to a Dropbox account controlled by the attacker without the victims knowledge or authorization. The vulnerability can be exploited in two ways, using a malicious app installed on the user’s device or remotely using drive-by techniques. It cannot, however, be exploited if the Dropbox app is installed (it does not even need to be configured, just installed)”]

