pwshub.com

Google Pulls Built-In Pixel Phone App After Security Alarms Raised

Google will remove a built-in app from its Pixel phone devices more than 90 days after intelligence contractor Palantir and the mobile security firm iVerify raised concerns about a major vulnerability in the software, Google said Wednesday night.

The application in question, Showcase.apk, was meant to help employees selling Pixel phones demonstrate features of the phone, iVerify says. But when the usually dormant app is activated, it accesses information from an Amazon Web Services site using the less-secure http protocol that makes it vulnerable to hacking.

The information about the Pixel app vulnerability was published Thursday in a report from iVerify that was aired by Palantir and the security company Trail of Bits. Palantir said it notified Google of the problem more than 90 days ago and its concerns were not addressed. Palantir subsequently stopped issuing Android phones to employees over concerns about the software's security.

Google said in an email to CNET that the app was developed by a third party, Smith Micro for Verizon, and said it does not represent an Android or Pixel vulnerability as it was only used for in-store devices. The company said the app is no longer being used.

"Exploitation of this app on a user phone requires both physical access to the device and the user's password," a Google spokesperson told CNET. "We have seen no evidence of any active exploitation. Out of an abundance of precaution, we will be removing this from all supported in-market Pixel devices with an upcoming Pixel software update. The app is not present on Pixel 9 series devices. We are also notifying other Android OEMs."

The news of a potential security issue with Pixel phones comes the same week that Google introduced its new line of Pixel phones at a Made By Google event in Mountain View, California. There, the company touted its new hardware line of phones, watches and earbuds as well as AI features in its Gemini software.

"While we don't have evidence this vulnerability is being actively exploited, it nonetheless has serious implications for corporate environments, with millions of Android phones entering the workplace every day," Rocky Cole, co-founder and chief operating officer at iVerify, said in a brief about the report on Thursday. "Google is essentially giving CISOs the impossible choice of accepting insecure bloatware or banning Android entirely."

iVerify said that the app in question cannot be removed by users; it's part of the firmware of Pixel phones. The app may pose a problem on other non-Pixel Android devices that were issued by Verizon containing the Showcase app.

Google said in an email that the Pixel update would be released "in the coming weeks," but did not issue any instructions to users on what they can do to protect their phones until that happens apart from keeping it out of the physical hands of hackers.

Watch this: Google Pixel 9, 9 Pro and 9 Pro XL Hands-On

03:24

Source: cnet.com

Related stories
1 month ago - If your Samsung Galaxy, Google Pixel or other Android device is feeling sluggish, try these tips to give it a new lease on life.
1 week ago - Companies like Apple and Google talk up AI for tasks like editing photos and drafting messages. But the burgeoning tech's value could also lie in boosting digital accessibility.
3 weeks ago - Commentary: Google's Pixel 9 is another reminder that today's AI features are in their early stages.
8 hours ago - For those who appreciate the finer things in life, these gifts are sure to impress.
1 day ago - It's not about one big feature, but how new elements like the Camera Control button and last year's Dynamic Island come together.
Other stories
14 minutes ago - After California passed laws cracking down on AI-generated deepfakes of election-related content, a popular conservative influencer promptly sued,...
37 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
37 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
38 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
38 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.