Article Details

Scrape Timestamp (UTC): 2024-05-14 17:07:06.102

Source: https://thehackernews.com/2024/05/android-15-introduces-new-features-to.html

Original Article Text

Click to Toggle View

Android 15 Introduces New Features to Block Malicious Apps from Capturing Sensitive Data. Google is unveiling a set of new features in Android 15 to prevent malicious apps installed on the device from capturing sensitive data. This constitutes an update to the Play Integrity API that third-party app developers can take advantage of to secure their applications against malware. "Developers can check if there are other apps running that could be capturing the screen, creating overlays, or controlling the device," Dave Kleidermacher, vice president of engineering for Android security and privacy, said. "This is helpful for apps that want to hide sensitive information from other apps and protect users from scams." Additionally, the Play Integrity API can be used to check if Google Play Protect is active and if the user's device is free of known malware before performing sensitive actions or handling sensitive data. Google, with Android 13, introduced a feature called restricted settings that by default blocks sideloaded apps from accessing notifications and requesting for accessibility services permissions. In the latest iteration of the mobile operating system, the feature is being expanded by seeking user approval prior to enabling permissions when installing an app via sideloading from web browsers, messaging apps, and file managers. The changes are squarely aimed at Android banking trojans that are known to abuse their permissions to the accessibility services API to perform overlay attacks and turn off security mechanisms on the device to harvest valuable data. That said, Android malware such as Anatsa has been observed circumventing restricted settings in recent months, indicating continued efforts on the part of threat actors to devise ways to breach security guardrails. "Developers can also opt-in to receive recent device activity to check if a device is making too many integrity checks, which could be a sign of an attack," Kleidermacher added. Alongside efforts to combat fraud and scams, Google is also stepping up cellular security by alerting users if their cellular network connection is unencrypted and if a bogus cellular base station or surveillance tool (e.g., stingrays) is recording their location using a device identifier. The tech giant said it's working closely with ecosystem partners, including original equipment manufacturers (OEMs), to enable these features to users over the next couple of years. That's not all. The company is tightening controls for screen sharing in Android 15 by automatically hiding notification content, thus preventing one-time passwords (OTPs) sent via SMS messages from being displayed during screen sharing. "With the exception of a few types of apps, such as wearable companion apps, one-time passwords are now hidden from notifications, closing a common attack vector for fraud and spyware," Kleidermacher said. Rounding off the new fraud and scam protection features, Google said it's diversifying Play Protect's on-device AI capabilities with live threat detection to better identify malicious apps. The approach leverages the Private Compute Core (PCC) to flag anomalous patterns on the device. "With live threat detection, Google Play Protect's on-device AI will analyze additional behavioral signals related to the use of sensitive permissions and interactions with other apps and services," Kleidermacher said. "If suspicious behavior is discovered, Google Play Protect can send the app to Google for additional review and then warn users or disable the app if malicious behavior is confirmed." Live threat detection also builds on a recently added capability that allows for real-time scanning at the code-level to combat novel malicious apps and help spot emerging threats.

Daily Brief Summary

MALWARE // Android 15 Enhances Security to Thwart Malicious App Activities

Google is introducing updated security features in Android 15 to protect users from malware by using an expanded Play Integrity API.

The enhancements will allow developers to detect if other apps might be capturing screen content or intercepting user data.

Newly introduced security protocols include measures against overlay attacks and the abuse of accessibility services permissions by banking trojans.

Some Android malware, like Anatsa, have found ways around existing security measures, prompting continuous improvements from Google.

Google plans to increase cellular security, alerting users to unencrypted connections and potential surveillance activities.

Screen sharing on Android 15 will now automatically obscure notification content, including one-time passwords, to prevent leakage during such sessions.

Play Protect's new live threat detection uses on-device AI to analyze behavior, improving the detection of malicious apps based on their activity patterns and interactions.

Google is collaborating with original equipment manufacturers (OEMs) to integrate these security features over the next few years, aiming for widespread adoption and enhanced user protection.