Nearly 40% of Android users at risk from screen hijack bug

An unpatched bug is leaving almost 40% of Android users at risk from screen-hijacking apps, a new report has found. And it's something that Google is unlikely to fix until the summer.

The problem, first spotted by researchers at Check Point, revolves around an oversight in Android permissions, and affects all phones running Android version 6.0.1 (Marshmallow) and above. According to Google's own stats, that's a whopping 38.3% of users left vulnerable.

Apps that are given permission to let elements sit on top of other app panes (like Facebook Messenger's chat bubbles, for instance) are at the heart of the problem. The permission for apps to do so relied on explicitly granting the 'SYSTEM_ALERT_WINDOW' permission to enable access, which was introduced in Android 6.0.0.

But so many popular apps were seeing complaints from users uncertain of how to activate the permission (particularly if they'd already once chosen not to restrict it) that Google removed the requirement for users to enable it altogether.

Screen ransoms

While legitimate apps breathed a sigh of relief, it also opened a backdoor through which dodgy apps could gain access to a device.

"As a temporary solution, Google applied a patch in Android version 6.0.1 that allows the Play Store app to grant run-time permissions, which are later used to grant SYSTEM_ALERT_WINDOW permission to apps installed from the app store",  explains Check Point.

"This means that a malicious app downloaded directly from the app store will be automatically granted this dangerous permission."

The Play Store is able to police itself through Google's 'Bouncer' software, which scans apps for any potentially malicious intent. But devious app developers may still be able to fly under the radar, and use the permission loophole to takeover a users screen, run phishing attacks or play havoc with the phone's UI.

Worst of all, Google has stated that the issue will be fixed by Android O's release – but that's not expected until late this summer.

In the meantime then, Android users should stick to trusted sources for the app downloads, and definitely steer clear of third-party Android app stores that are known to be rife with malware.

Via The Register

Gerald Lynch

Gerald is Editor-in-Chief of iMore.com. Previously he was the Executive Editor for TechRadar, taking care of the site's home cinema, gaming, smart home, entertainment and audio output. He loves gaming, but don't expect him to play with you unless your console is hooked up to a 4K HDR screen and a 7.1 surround system. Before TechRadar, Gerald was Editor of Gizmodo UK. He is also the author of 'Get Technology: Upgrade Your Future', published by Aurum Press.

Latest in Android
Two Android phones on a green and blue background showing Google Messages
Google Messages just added a fun upgrade to one of its best chat features
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
A phone displaying the Google Messages logo
Google Messages could finally be getting this WhatsApp-style group chat feature
Android 16 logo on a phone
Android 16 Beta 3 has arrived – here are the 4 features I think will be the most useful
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
Android 16 logo on a phone
Android 16 beta users are reporting major battery drain issues – but I’m not too worried about it
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news