Social News XYZ     

US researchers find crypto bugs in 306 popular Android apps

US researchers find crypto bugs in 306 popular Android apps

New York, Sep 8 (SocialNews.XYZ) A team of US researchers has developed a tool that can find cryptocurrency bugs in Android apps. Using the tool, they discovered crypto bugs in 306 popular Android applications.

Named 'CRYLOGGER', the custom tool was used to test 1,780 Android apps across 33 different Google Play Store categories, ZDNet reported on Tuesday.

 

The research team from Columbia University found crypto bugs in 306 popular Android apps and none was patched.

"Only 18 of 306 app developers replied to the research team and only eight engaged with the team after the first email," the report said, quoting the researchers.

"All the apps are popular: they have from hundreds of thousands of downloads to more than 100 million," the research team was quoted as saying.

While some crypto bugs were in the app's code, some common vulnerabilities were introduced as part of Java libraries used as part of the apps.

"Since none of the developers fixed their apps and libraries, researchers refrained from publishing the names of the vulnerable apps and libraries, citing possible exploitation attempts against the apps' users".

The new tool, said the researchers, can be used by Android developers as a complementary utility to CryptoGuard.

Just like CryptoGuard, CRYLOGGER's code is also available on open source repository GitHub.

Source: IANS

Facebook Comments
US researchers find crypto bugs in 306 popular Android apps

About Gopi

Gopi Adusumilli is a Programmer. He is the editor of SocialNews.XYZ and President of AGK Fire Inc.

He enjoys designing websites, developing mobile applications and publishing news articles on current events from various authenticated news sources.

When it comes to writing he likes to write about current world politics and Indian Movies. His future plans include developing SocialNews.XYZ into a News website that has no bias or judgment towards any.

He can be reached at gopi@socialnews.xyz