A serious vulnerability has been found in the third-party Software Development Kit (SDK) Android used by a number of crypto wallet applications. This finding was disclosed by the Microsoft Defender Security Research Team.



In its official report, this flaw impacts more than 30 million installations of crypto wallet applications, with total exposure reaching more than 50 million app installations. The digital wallet ecosystem is the most at risk because it stores assets and user data.

If exploited, this vulnerability could open access to Personal Identifiable Information (PII), user credentials, and even sensitive financial data stored in the app’s private directory.

The issue stems from a component in the EngageLab SDK named MTCommonActivity that is automatically added during the app build process. Because the component can be accessed by other applications on the same device, a security vulnerability arises.

As a result, a malicious application can send fake (intent) commands so that the wallet app processes them with trusted permissions. Even so, Microsoft states that there is no evidence that this vulnerability has been actively exploited.
#GateLaunchesPreIPOS
#GateSquareAprilPostingChallenge
View Original
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin