This major Android bug may have led to the creation of awful new malware apps

app security
(Image credit: Shutterstock.com) (Image credit: Shutterstock.com)

Following a major security leak, devices from some of the world’s biggest Android smartphone manufacturers are vulnerable to malicious apps that operating systems are treating as trusted.

The news comes from Google’s Android Partner Vulnerability Initiative’s (APVI) Łukasz Siewierski, who publicly disclosed the vulnerability in November 2022.

As noted by 9to5Google, Siewierski's disclosure doesn't directly reveal which major Android manufacturers have had their platform signing keys leaked, but virus scans of some affected files have confirmed that Samsung, LG, Xiaomi, Mediatech, szroco, and Revoview devices are affected, but this is a developing and incomplete list.

Abusing trusted apps

To quote Mishaal Rahman, Technical Editor for cloud platform Esper, "this is bad. Very, very bad." 

The vulnerability is allowing threat actors to create malicious apps with system-level privileges, and even integrate malicious code into pre-existing, non-malicious and trusted Android applications. And it's because of platform signing keys.

A platform signing key is an element that the endpoint uses to make sure the operating system running is legitimate. They're used to create platform-signed apps, those that a device manufacturer has verified as safe and free of malware.

Should a threat actor obtain these keys, they’d be able to use the Android’s “shared user ID” system to craft a malicious application with full system access. 

To make matters even worse, it’s not just newly-built apps that can be abused like this. Already installed apps still need to be signed regularly, meaning threat actors could side-load malware into trusted apps in short order. 

Following resigning, a simple app update, which Android then wouldn’t see as problematic, would be enough to infect a device.

The issue was first spotted by Google in May 2022, and the company claims that all affected manufacturers have taken "remediation measures to verify the user impact", although no further details were given. 

It's still unclear if these measures have worked, as 9to5Google also claimed some of the vulnerable keys were used in Android apps from Samsung within the last few days at time of writing.

Still, Google said Android phones are safe in a number of ways, including through Google Play Protect, OEM mitigations, and more. Apps residing in the Play Store are safe, too, apparently. 

“OEM partners promptly implemented mitigation measures as soon as we reported the key compromise. End users will be protected by user mitigations implemented by OEM partners," a spokesperson for the company said.

"Google has implemented broad detections for the malware in Build Test Suite, which scans system images. Google Play Protect also detects the malware. There is no indication that this malware is or was on the Google Play Store. As always, we advise users to ensure they are running the latest version of Android.”

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
A padlock image floating over a smartphone.
Best secure smartphones of 2025
Google Pixel 7 Pro hands on front Hazel
The best Android antivirus apps for 2025
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
App stores are increasingly becoming a major security worry
An Android phone being held in the hand
Google is ramping up Android security protection with new Android app safety tools
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC