Google Discovered Epic Vulnerability in Epic's Fortnite Android Installer
Google has revealed that it discovered a serious vulnerability in Epic's first Fortnight installer for Android, potentially allowing any app with the WRITE_EXTERNAL_STORAGE permission to substitute the APK immediately later the download is completed and the fingerprint is verified.
According to an issutracker postal service by a Googler, the flaw immune cyber-criminals to 'easily' bear out an attack using a FileObserver, post-obit which, the Fortnite Installer will proceed to install the substituted (imitation) APK.
As tin can be seen from the thread, Google manifestly notified Epic about its discovery on Baronial 15th, following which, Epic had 90-days to patch up the flaws, in line with standard industry practices. As it turns out, the vulnerability was patched up within just a couple of days, with the company rep announcing the deployment of the patch on the 17th.
According to Epic InfoSec, the patch will modify the default APK storage directory from external to internal storage, thereby helping prevent Man-in-the-Disk (MITD) attacks during the install period.
What'due south interesting is that Epic nevertheless requested Google to not disclose the flaw for the full 90-day flow, then that its users accept time to patch their installers. However, Google didn't go on board with the time-frame, and ended upward opening the thread to the public just seven days after the patch was deployed, in line with the company's standard disclosure practices.
Epic Games CEO Tim Sweeney expressed his dissatisfaction at Google's early disclosure, calling it an 'irresponsible' decision that can endanger innocent users. In a argument to Android Central, he said, "it was irresponsible of Google to publicly disembalm the technical details of the flaw so apace, while many installations had not nonetheless been updated and were however vulnerable".
"Google's security assay efforts are appreciated and benefit the Android platform, notwithstanding a visitor as powerful equally Google should practice more responsible disclosure timing than this, and non endanger users in the course of its counter-PR efforts against Epic'southward distribution of Fortnite exterior of Google Play"
To understand why Ballsy and Google are so utterly dissatisfied with each other correct now, one needs to know the recent backstory surrounding the launch of Fortnite on Android. Fifty-fifty as the game finally launched on Android long after making its debut on iOS, Epic and Tencent decided to distribute the game through their ain platform, rather than via the Google Play Store.
It was largely a concern decision for the game's publishers, who didn't want to share the revenue from the game with Google, which takes 30 per centum of all purchases made through the Play Store. Goes without saying, the tech giant wasn't amused by the decision, given that information technology apparently stands to lose $50 meg this yr alone because of the situation.
Source: https://beebom.com/google-discovered-vulnerability-fortnite-android/
Posted by: rasmussenmileat1975.blogspot.com

0 Response to "Google Discovered Epic Vulnerability in Epic's Fortnite Android Installer"
Post a Comment