| ▲ | Retr0id 5 hours ago | |||||||||||||||||||||||||||||||
> the malware captures their two-factor authentication codes Aren't we supposed to have sandboxing to prevent this kind of thing? If the malware relies on exploiting n-days on unpatched OSes, they could bypass the sideloading restrictions too. | ||||||||||||||||||||||||||||||||
| ▲ | UncleMeat 4 hours ago | parent [-] | |||||||||||||||||||||||||||||||
Codes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app. On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||