{"id":280320,"date":"2024-05-06T06:50:21","date_gmt":"2024-05-06T13:50:21","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=331759"},"modified":"2025-07-01T16:34:04","modified_gmt":"2025-07-01T23:34:04","slug":"update-or-uninstall-these-android-apps-now-if-you-want-to-avoid-problems","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/update-or-uninstall-these-android-apps-now-if-you-want-to-avoid-problems\/","title":{"rendered":"Update or uninstall these Android apps now if you want to avoid problems"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Microsoft<\/strong> has issued an alert about a serious security vulnerability in Android, known as <strong>&#8220;Dirty Stream&#8221;<\/strong>, which puts at risk the integrity of several apps with hundreds of millions of installations. This security breach, which <strong>allows malicious apps to take control of legitimate apps<\/strong>, is related to the <strong>ContentProvider<\/strong> system, used by many popular Android apps and essential for communication between apps and file sharing in the Android ecosystem.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Android 14\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/888d43f8-368b-4775-802c-936973a5b407\/873581939\/android-14-2023-04-13_17-33-29.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Android 14<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/android-14.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/android-14.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Two apps affected by this vulnerability are <strong>File Manager<\/strong> from <strong>Xiaomi<\/strong> (the default file manager for Xiaomi mobile phones) and <strong>WPS Office<\/strong>, with over 1 billion and 500 million installations respectively. <a href=\"https:\/\/en.softonic.com\/articles\/microsoft-fixes-two-zero-day-exploits-that-could-be-used-to-sneak-malware-onto-your-system\" target=\"_blank\" rel=\"noopener\" title=\"\">Microsoft<\/a> discovered that these apps were <strong>vulnerable to arbitrary code execution<\/strong>, but both have released updates to fix the issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The complexity of Dirty Stream lies in how it manipulates the ContentProvider system. Hackers <strong>can create &#8220;custom intents&#8221; to bypass security measures<\/strong>, sending disguised malicious files to other apps through these intents. Once compromised, a vulnerable app can overwrite critical files, which can result in the execution of unauthorized code, <strong>data theft, and even hijacking of the app without the user&#8217;s knowledge<\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-1024x576.jpg\" alt=\"\" class=\"wp-image-280323\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-1024x576.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-300x169.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-768x433.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-800x450.jpg 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-664x374.jpg 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-238x134.jpg 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-436x246.jpg 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-370x208.jpg 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1-304x170.jpg 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/05\/Troyano-Agent-Tesla-malware-1024x576-1.jpg 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">&#8220;The arbitrary code execution can give a criminal full control over the behavior of an app,&#8221; Microsoft said in a <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/05\/01\/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">blog post<\/a> a few days ago. &#8220;On the other hand, <strong>token theft<\/strong> can give a criminal access to user accounts and confidential data.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s research revealed that Dirty Stream is not an isolated problem, but it <strong>affects many popular Android apps<\/strong> due to incorrect implementations of the ContentProvider system. Although some vulnerable apps have been identified and patched, <strong>it is difficult to determine the full extent of the threat<\/strong>, as many other legitimate apps could be at risk.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Android 14\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/888d43f8-368b-4775-802c-936973a5b407\/873581939\/android-14-2023-04-13_17-33-29.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Android 14<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/android-14.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/android-14.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has issued an alert about a serious security vulnerability in Android, known as &#8220;Dirty Stream&#8221;, which puts at risk the integrity of several apps with hundreds of millions of installations. This security breach, which allows malicious apps to take control of legitimate apps, is related to the ContentProvider system, used by many popular Android &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/update-or-uninstall-these-android-apps-now-if-you-want-to-avoid-problems\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Update or uninstall these Android apps now if you want to avoid problems&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9256,"featured_media":280321,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-280320","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/280320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=280320"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/280320\/revisions"}],"predecessor-version":[{"id":313365,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/280320\/revisions\/313365"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/280321"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=280320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=280320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=280320"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=280320"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=280320"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=280320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}