Application security, Vulnerability Management

EngageLab SDK bug threatened expansive Android crypto wallet compromise

Adobe Stock

Popular third-party Android software development kit EngageLab SDK has been impacted by an already addressed intent redirection flaw, which could have been exploited to compromise Android apps installed over 50 million times, including cryptocurrency wallets with more than 30 million downloads, according to The Hacker News.

Threat actors could have harnessed the impacted apps' trusted context to execute a malicious payload enabling unwanted protected component access, sensitive data compromise, and privilege escalation, a report from the Microsoft Defender Security Research Team revealed. All of the affected apps have since been removed from the Google Play Store. While no in-the-wild exploitation of the flaw was discovered, such findings were noted by Microsoft to be indicative of the potentially broad impact of third-party SDK vulnerabilities.

"Apps increasingly rely on thirdparty SDKs, creating large and often opaque supplychain dependencies. These risks increase when integrations expose exported components or rely on trust assumptions that arent validated across app boundaries," Microsoft added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds