Google has been promoting to users that downloading and installing Android apps from the Play Store is a trustworthy and highly secure source. However, this security must be based on the application itself being as strong as the Google Play Store service, and the same level of security must be in the code used by developers to truly make the defense line strong both inside and outside.

Google Play Store apps are also unsafe, with many popular Android apps still using outdated versions of core libraries
While Google has blocked a recent security flaw from the Play Store’s core libraries, app developers are indirectly exposing users and their apps to risk because they haven’t followed suit. As the name suggests, the Google Play core library is one of the most basic components of the entire GMS service. It is like a box for interacting with Google Play services from within the application, from dynamic source code to the required download level, providing resources for specific areas, and interacting with the review mechanism of the Google Play Store. Currently, almost all applications in the Play Store use this core library, including the Microsoft Edge browser, Whatsapp, Instagram, Facebook, and Google’s own Chrome browser, making this core library an important key.

Unfortunately, there is a critical flaw in the core library that could allow an unscrupulous person to exploit the vulnerability to execute malicious code, which could become a huge problem if not addressed. Fortunately, the Play core library was patched last April, and the vulnerability was not publicly disclosed until August. However, security personnel warn that although Google has fixed it, there are still many application developers who have not kept up with the times and updated to the latest version of the core library. The video below shows how this vulnerability affects user security:
Unlike server patching on Google’s side, app developers must patch their core libraries by updating their apps, and an estimated 13% of apps have yet to catch up.Check Point Listing the vulnerable applications, Viber, Booking.com, Grindr, Moovit and Cisco said they have patched the vulnerabilities, and other applications may also patch the vulnerabilities in the future:

◎Data source:Check Point
Source: KOCPC Chinese