Google Pixel Phones Have Security Risks Revealed By iVerify

| Updated on August 23, 2024
google pixel

iVerify discovers critical vulnerabilities in Google Pixel devices that deliver a security risk to millions of users. The vulnerabilities bring rise to cyber threats, spyware installations, man-in-the-middle attacks, and more.

According to the mobile security firm, iVerify, an Android package called “Showcase.apk” has been pre-installed in the system. Smith Micro for Verizon developed the application to launch retail store demos on devices. Additionally, the application downloads the configuration file over an unsecured HTTP connection, leading to multiple vulnerabilities. The issue of Android vulnerability has been present in Google Pixel since 2017. 

Google Pixel Series

“I’ve seen a lot of Android vulnerabilities, and this one is unique in a few ways and quite troubling,” says Rocky Cole, chief operating officer of iVerify and a former US National Security Agency analyst. “When Showcase.apk runs, it can take over the phone. But the code is, frankly, shoddy. It raises questions about why third-party software that runs with such high privileges so deep in the operating system was not tested more deeply. It seems to me that Google has been pushing bloatware to Pixel devices around the world.”

Palantir, the software platform for big data analytics, worked with iVerify to disclose the Android vulnerabilities in Google Pixel. Dane Stuckey, chief security officer of Palantir, expressed that Google was slow and opaque in response. Eventually, the company announced its decision to terminate Android devices. 

Moreover, iVerify also represents that the “Showcase.apk” is turned off by default but there might be multiple methods to switch it. The attacker or hacker must need physical access to the phone and system password for exploitable vulnerability. This means that to take control over a phone or device, the attacker should need to turn on the Showcase settings.

Apart from this, Ed Fernandez spoke on behalf of Google that Android will remove the Showcase app from all Pixel series in the coming weeks.   

Related Post

By subscribing, you accepted our Policy

×