Millions of Google Pixel phones may be vulnerable to a deadly cyber attack

The cybersecurity company iVerify has recently discovered a serious vulnerability that affects millions of Pixel smartphones worldwide and has published its findings in a new report.

According to the document, the offending software in question is called Showcase.apk. It was originally developed by Smith Micro Software for demonstration devices within Verizon stores.

Google Chrome DOWNLOAD

Thanks to this, employees have deep access to the many features of a Pixel phone in order to ‘demonstrate how they work’ to interested customers.

Normally, Showcase is inactive and does nothing. However, a skilled hacker may activate it through a backdoor.

What can this APK do on Google phones

The APK (Android Package Kit) receives its configuration file from an insecure domain on Amazon Web Services. In theory, a malicious actor could intercept these connections or impersonate the website’s identity and inject malware or spyware into a Pixel phone. Additionally, since Showcase has ‘excessive system privileges,’ it is easy for cybercriminals to compromise a target.

What is particularly terrifying is that Showcase has been part of the Google Pixel ecosystem since September 2017. And the worst part is that the average user cannot remove the APK through the standard uninstallation process, as it is considered a system-level application. iVerify claims that ‘only Google can fix’ this issue.

No matter how bad things are, there is good news. First of all, it seems that no one, not even hackers, knew about the exploit. A Google spokesperson told The Washington Post that they have not seen any attacks that can be attributed to Showcase.

Google Chrome DOWNLOAD

And they stated that there is no evidence of ‘active exploitation’ and even suggested that such an attack ‘would be unlikely.’

Google is aware of the problem. The tech giant told Forbes that they are taking measures ‘out of an abundance of caution’ and plan to deploy a patch to all ‘compatible Pixel devices on the market.’ However, don’t worry about the Pixel 9 series, as none of the four models have Showcase.apk.

Author: Chema Carvajal Sarabia

{ "de-DE": "Journalist, spezialisiert auf Technologie, Unterhaltung und Videospiele. Über das zu schreiben, was mich begeistert (Gadgets, Spiele und Filme), ermöglicht es mir, bei Verstand zu bleiben und mit einem Lächeln im Gesicht aufzuwachen, wenn der Wecker klingelt. PS: Das stimmt nicht 100% der Zeit.", "en-US": "Journalist specialized in technology, entertainment and video games. Writing about what I'm passionate about (gadgets, games and movies) allows me to stay sane and wake up with a smile on my face when the alarm clock goes off. PS: this is not true 100% of the time.", "es-ES": "Content Manager - Periodista especializado en tecnología, entretenimiento y videojuegos. Escribir sobre lo que me apasiona (cacharros, juegos y cine) me permite seguir cuerdo y despertarme con una sonrisa cuando suena el despertador. PD: esto no es cierto el 100 % de las veces.", "fr-FR": "Journaliste spécialisé dans la technologie, le divertissement et les jeux vidéo. Écrire sur ce qui me passionne (gadgets, jeux et films) me permet de rester sain d'esprit et de me réveiller avec le sourire aux lèvres quand le réveil sonne. PS : cela n'est pas vrai 100 % du temps.", "it-IT": "Giornalista specializzato in tecnologia, intrattenimento e videogiochi. Scrivere di ciò che mi appassiona (gadget, giochi e film) mi permette di mantenere la sanità mentale e di svegliarmi con un sorriso sul viso quando suona la sveglia. PS: questo non è vero al 100% del tempo.", "ja-JP": "", "nl-NL": "", "pl-PL": "", "pt-BR": "Jornalista especializado em tecnologia, entretenimento e videogames. Escrever sobre o que me apaixona (gadgets, jogos e filmes) me permite manter a sanidade e acordar com um sorriso no rosto quando o despertador toca. PS: isso não é verdade 100% do tempo.", "social": { "email": "chemacs91@gmail.com", "facebook": "", "twitter": "https://twitter.com/chematopetazo", "linkedin": "" } }