More Than You Signed Up For: Exposing Gaps in the Validation of Android’s App Signing
摘要
Android’s ubiquitous flexibility has helped it to become one of the most widely used mobile operating systems in the world. However, the convenient and extensive access to phone resources adopted by Android has revealed inefficiencies of its existing protections. Among these protections is application (app) signing. This process is intended to maintain the integrity of the app after it is released, and it provides users with confidence in the app’s authenticity. We analyze the functionality of Android signature verification and identify the logical gaps in the process that can be used to hide a malicious payload. We demonstrate the security implications of these gaps.