Blog | G5 Cyber Security

DroppedIn: New Vulnerability Discovered in Dropbox SDK for Android

IBM X-Force Application Security Research Team has discovered a vulnerability in the Dropbox SDK for Android (CVE-2014-8889) The vulnerability allows attackers to connect applications on mobile devices to a Dropbox account controlled by the attacker without the victims knowledge or authorization. The vulnerability can be exploited in two ways, using a malicious app installed on the user’s device or remotely using drive-by techniques. It cannot, however, be exploited if the Dropbox app is installed (it does not even need to be configured, just installed)”]

Source: https://securityintelligence.com/droppedin-remotely-exploitable-vulnerability-in-the-dropbox-sdk-for-android/

Exit mobile version