ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A flaw in Android's built-in browser lets fake websites trick users into entering passwords and credit card info. Attackers can create convincing fake sites that steal real data when you log in or pay.
- Report priority
- Medium
- Targets
- Android
How it works
- Fake websites use a trick to bypass Android's normal security checks.
- When you visit a fake site, the browser lets it ask for your password or credit card details without warning.
- Once you enter them, the fake site sends your info to the attacker's real server instead of the real company's site.
- This happens because the browser does not properly check if a site is really who it claims to be before letting it ask for sensitive data.
What to do
Watch for updates from Google about a patch. In the meantime, avoid clicking on links from unknown sources, check website URLs carefully, and use a trusted password manager to monitor for data leaks. If you suspect your data was stolen, contact your bank or the affected service immediately.
Technical details
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results.
An exposed system stays exposed. A package looks useful right up until it isn’t.