• Latest
  • Trending
Amazon fixes high-severity vulnerability in Android Photos app

Amazon fixes high-severity vulnerability in Android Photos app

June 30, 2022
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023
EU Cybersecurity Agency Warns Against Chinese APTs

EU Cybersecurity Agency Warns Against Chinese APTs

February 20, 2023
How Your Storage System Will Still Be Viable in 5 Years’ Time?

How Your Storage System Will Still Be Viable in 5 Years’ Time?

February 20, 2023
The Broken Promises From Cybersecurity Vendors

Cloud Infrastructure Used By WIP26 For Espionage Attacks on Telcos

February 20, 2023
Instagram and Facebook to get paid-for verification

Instagram and Facebook to get paid-for verification

February 20, 2023
YouTube CEO Susan Wojcicki steps down after nine years

YouTube CEO Susan Wojcicki steps down after nine years

February 20, 2023
Inaugural AfCFTA Conference on Women and Youth in Trade

Inaugural AfCFTA Conference on Women and Youth in Trade

September 6, 2022
Instagram fined €405m over children’s data privacy

Instagram fined €405m over children’s data privacy

September 6, 2022
8 Most Common Causes of a Data Breach

5.7bn data entries found exposed on Chinese VPN

August 18, 2022
Fibre optic interconnection linking Cameroon and Congo now operational

Fibre optic interconnection linking Cameroon and Congo now operational

July 15, 2022
Ericsson and MTN Rwandacell Discuss their Long-Term Partnership

Ericsson and MTN Rwandacell Discuss their Long-Term Partnership

July 15, 2022
  • Consumer Watch
  • Kids Page
  • Directory
  • Events
  • Reviews
Wednesday, 29 March, 2023
  • Login
itechnewsonline.com
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion
Subscription
Advertise
No Result
View All Result
itechnewsonline.com
No Result
View All Result

Amazon fixes high-severity vulnerability in Android Photos app

by ITECHNEWS
June 30, 2022
in Infosec, Leading Stories
0 0
0
Amazon fixes high-severity vulnerability in Android Photos app

Amazon has confirmed and fixed a vulnerability in its Photos app for Android, which has been downloaded over 50 million times on the Google Play Store.

Amazon Photos is an image and video storage application that enables users to seamlessly share their snaps with up to five family members, offering powerful management and organization features.

YOU MAY ALSO LIKE

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Data Leak Hits Thousands of NHS Workers

Amazon Photos on the Play Store
Amazon Photos on the Play Store

The flaw, discovered by researchers at Checkmarx, lies in a misconfiguration of an app component, resulting in its manifest file being externally accessible without authentication.

Exploiting this bug could have enabled a malicious app installed on the same device to snatch Amazon access tokens used for Amazon APIs authentication.

These APIs might contain sensitive personal information like full name, email, and physical address, while others like the Amazon Drive API hold user files.

Exploiting the flaw

The vulnerable component is “com.amazon.gallery.thor.app.activity.ThorViewActivity”, which, when launched, triggers an HTTP request that contains a header with the user’s token.

The vulnerable activity component
The vulnerable activity component (Checkmarx)

Checkmarx researchers found that an external app could easily launch the vulnerable activity and trigger the request at will, sending the token to an actor-controlled server.

Request containing the Amazon token received at a malicious endpoint
Request containing the Amazon token received at a malicious endpoint (Checkmarx)

The analysts explored various exploitation scenarios with the acquired token, such as performing file actions on the victim’s Amazon Drive cloud storage, erasing history so that deleted data is irrecoverable, and more.

“With all these options available for an attacker, a ransomware scenario was easy to come up with as a likely attack vector,” details Checkmarx

“A malicious actor would simply need to read, encrypt, and re-write the customer’s files while erasing their history.”

The same token might be used by other Amazon APIs, like Prime Video, Alexa, Kindle, etc., so the exploitation potential could be far-reaching.

Disclosure and fix

Checkmarx reported the issue to Amazon on November 7, 2021, and the internet giant confirmed the reception the next day, classifying it as a high-severity vulnerability.

On December 18, 2021, Amazon informed Checkmarx that they had resolved the issues via a security update deployed into production. However, users of the app were never informed of the potential exposure.

We have reached out to Amazon to ask if they noticed any signs of exploitation of the vulnerability and whether there have been reports of unauthorized Amazon API access during that period, and a spokesperson has provided us with the following comment:

At Amazon, privacy and security are foundational to how we design and deliver devices, features, and experiences. We appreciate the work of independent security researchers who help bring potential issues to our attention.

We released a fix for this issue soon after it was brought to our attention. We have no evidence that sensitive customer information was exposed as a result of this issue.

Source: Bill Toulas
Via: bleepingcomputer
Tags: Amazon fixes high-severity vulnerability in Android Photos app
ShareTweetShare
Plugin Install : Subscribe Push Notification need OneSignal plugin to be installed.

Search

No Result
View All Result

Recent News

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023
EU Cybersecurity Agency Warns Against Chinese APTs

EU Cybersecurity Agency Warns Against Chinese APTs

February 20, 2023

About What We Do

itechnewsonline.com

We bring you the best Premium Tech News.

Recent News With Image

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023

Recent News

  • Co-Creation Hub’s edtech accelerator puts $15M towards African startups February 20, 2023
  • Data Leak Hits Thousands of NHS Workers February 20, 2023
  • EU Cybersecurity Agency Warns Against Chinese APTs February 20, 2023
  • How Your Storage System Will Still Be Viable in 5 Years’ Time? February 20, 2023
  • Home
  • InfoSec
  • Opinion
  • Africa Tech
  • Data Storage

© 2021-2022 iTechNewsOnline.Com - Powered by BackUPDataSystems

No Result
View All Result
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion

© 2021-2022 iTechNewsOnline.Com - Powered by BackUPDataSystems

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Go to mobile version