Skip to main content

Exploit:Android/Masterkey

Classification

Category:

Malware

Platform:

Android

Type:

Exploit

Aliases:

  • Aliases for public viewing

Summary

Exploit:Android/Masterkey identifies code designed to exploit a known vulnerability in the way the Android operation system verifies the authenticity of an app.

Removal

Technical Details

In July [2013], security researchers publicly announced the discovery of a vulnerability in cryptographic signature verification for Android apps that, if exploited, would allow an attacker to modify a legitimate apps code without affecting its cryptographic signature - essentially keeping the tampering from being detected during verification. Shortly after the announcement, researchers were able to find samples of such modified apps being distributed.

Google was reportedly notified of the "Masterkey" issue earlier in the year, and at the time of the announcement had fixed the issue in the Android open source codebase. Users would however still need to wait for a firmware update from their device manufacturer in order to receive the patched code.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.