Get a Pentest and security assessment of your IT network.

Cyber Security

LG Handsets’ App Update Doesn’t Verify SSL Cert, Could Lead to Hijacking

Many smartphones manufactured by LG contain a vulnerability that can allow an attacker to replace an APK file with a malicious file of his choice. Researchers at Search-Lab in Hungary found that the update process for these apps does not validate the security certificate presented by the server on the other end, opening users up to man-in-the-middle attacks. LG plans to fix the bug only in new handsets and won’t push a fix to existing phones. LG officials said they are looking into the details of the report.

Source: https://threatpost.com/researcher-says-lg-app-update-mechanism-doesnt-verify-ssl-cert/113522/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security