• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Microsoft discovers a new Android vulnerability that shows how pre-installed system apps can be used as an attack vector

Microsoft discovers a new Android vulnerability that shows how pre-installed system apps can be used as an attack vector

Claire by Claire
June 1, 2022 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

The value of mobile phones in modern people’s lives is not only a communication tool, but also a gateway for hackers to access all users’ personal data. Global security companies have been working hard to ensure attack vectors are eliminated as quickly as possible. recentlyMicrosoft discovery blocks a critical vulnerability affecting many Android phones, uncovered a problematic framework that was bundled with many of the system apps that come pre-installed on Android phones.

Microsoft discovers a new Android vulnerability that shows how pre-installed system apps can be used as an attack vector

The issue occurs with a framework developed by MCE Systems, which is bundled with a number of system apps provided by many Android phone carriers, including self-diagnostic tools, and these apps are also available in the Google Play Store. So far, this vulnerability can completely bypass Google’s automatic security detection, but after Microsoft proactively communicated with Google, the latter has included the vulnerability in the detection list.

Since the framework is part of a pre-installed system app, it has a lot of permissions that allow it to gain almost complete control over the phone as part of its functionality. It can access and operate volume control, silently and quickly take pictures from the phone lens, control and obtain information from NFC, Bluetooth and Wi-Fi, view the location of the phone, access content in the storage space (such as files, media), and more. This usually shouldn’t be a problem, as only the privileged system application in question can interact with the framework.

However, Microsoft found that the design of the framework allowed attackers to plant a persistent backdoor to silently spy on the target, or to inject unsafe JavaScript code to gain substantial control over the device in question. MCE Systems worked with Microsoft to address this issue, and it has implemented a different software design that makes it less vulnerable to this type of attack by no longer polling for asynchronous job results (which was the culprit!). Along the way, the companies also noticed that Google provides an API on Android 5 and above that can be used to replace the company’s previous less secure approach, so MCE Systems is now using Google’s solution on supported devices. 98% of Android phones should now have a newer version of Android than this.

While the company responsible for the framework has fixed the issue, apps using the framework will still need to be updated to be patched. So far, Microsoft says that many of the apps provided by carriers have started to update, but there may still be older versions still in use. In this sense, make sure you have activated the auto-update feature on the Play Store to get the fix as soon as possible. Since it is unclear how many telecom operators around the world are using this framework to build their own service applications, it may take quite a while to fix it on all telecom-issued devices.

Source: KOCPC Chinese

Tags: Androidback doorframeGoogle Play StoreInternet securityloopholesMicrosoftmobile devicePre-installed appsTelecommunications provider

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology