Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Malicious hackers could exploit flaws in Android for Work to nab sensitive data

Add as a preferred source on Google

One of the pillars of Google’s enterprise-focused “work features in Android platform,” previously called Android for Work, is security. But a newly discovered exploit demonstrated at the RSA conference in San Francisco on February 16 showed how an attacker could view, steal, and even manipulate content on a corporate Android smartphone without tipping off IT administrators.

The flaw, discovered by Yair Amit, chief technology officer of cybersecurity firm Skycure, has to do with the way Android for Work handles “sandboxes,” or protects user profiles. The service operates on the idea of a “work” profile with business-level controls, enterprise applications, corporate email, and secure documents on a smartphone or tablet. This secure profile effectively acts as a separate user, though it shares icon badges and notifications with the personal profile.

Recommended Videos

This concept of sandboxing — creating a secure container where apps outside the work profile can’t access data inside it — is key to Android for Work’s conceit. But it isn’t bulletproof.

One potential line of attack involves Android’s notifications framework. Incoming Android for Work messages are designated with a red briefcase icon in Android’s notifications window, giving the impression that they remain segregated from those in the personal profile.

But notifications on Android are a device-level permission, meaning apps in the personal profile can potentially manipulate the content of notifications from the work profile. Malicious software could view sensitive incoming work emails, calendar appointments, file attachments, and other messages, for example, and could transmit that information to a remote server.

The second line of attack exploits a flaw in Android’s Accessibility Service, the Android component that provides usability enhancements for impaired users. It necessarily has access to virtually all of Android’s content and controls, making apps that acquire permission to use it particularly dangerous — and difficult to detect. For instance, an app could use Android’s Draw Over Apps feature, which allows apps to lay text and graphics on top of other apps, to trick a user into activity Accessibility Service or Notifications without their knowledge.

That’s not to suggest the attacks can’t be mitigated. Android 6.0 Marshmallow requires users to manually allow apps to create system overlays by changing permissions in the settings menu. And the Notifications attack requires a user to grant extraordinary permissions to an installed app. Still, Amit notes the relative ease of circumventing Android for Work’s sandboxing method by exploiting the “illusion” of security.

“The interesting thing about both of these […] methods of defeating the Android for Work profile separation is that the device and the Android operating system remain operating exactly as designed and intended,” Amit said.

“It is the user who must be tricked into placing the software on the device and activating the appropriate services that allow the malware access to sensitive information. [The] illusion of a secure container […] tends to allow people to let their guard down in the belief that the environment itself is a sufficient security mechanism to protect data.”

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Android can now back up more of your phone, but Google is also letting you say no
Users can opt out of message, call history, and settings backups even as Google expands Drive backup to cover documents stored locally.
Electronics, Mobile Phone, Phone

Google is reshaping Android backup in two directions at once. New switches let you stop several types of phone data from being uploaded, while a separate Documents feature can save local files to Google Drive.

The controls cover messages, call history, and device settings. Each category can now be turned off individually instead of being backed up automatically, joining the newer per-app switches already appearing through Google Play services.

Read more
Fresh Galaxy Z Fold 8 leak suggests US buyers won’t escape a price hike
A new report puts the Galaxy Z Fold 8 Ultra at $2,099 in the US, a $100 jump over last year's model.
Leaked render of Samsung Galaxy Z Fold 8.

Samsung has confirmed its next Galaxy Unpacked event for July 22, where it's expected to unveil its next-gen foldables. Recent reports suggest the devices may be priced significantly higher in Europe compared to their predecessors. Now, a new leak claims the same could be true for the US market as well.

US buyers could see a $100 jump

Read more
The Fold 8 Ultra could finally get Samsung’s best cameras
Better low-light, Video LUT, dual recording, and S26 Ultra-grade resolution.
Electronics, Speaker, White Board

The biggest complaint about every Galaxy Z Fold, even the Fold 7 that launched last year, has been the same one: great phone, mediocre cameras. 

Samsung has always reserved its best camera hardware for the Galaxy S Ultra line, leaving Fold buyers with a somewhat compromised experience. According to a new leak, the Galaxy Z Fold 8 Ultra could change that.

Read more