{"id":4933,"date":"2024-08-19T12:31:49","date_gmt":"2024-08-19T17:31:49","guid":{"rendered":"https:\/\/www.darkreading.com\/remote-workforce\/every-google-pixel-phone-has-a-verizon-app-backdoor"},"modified":"2024-08-19T12:31:49","modified_gmt":"2024-08-19T17:31:49","slug":"every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/19\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor\/","title":{"rendered":"Every Google Pixel Phone Has a Verizon App that Doubles As a Backdoor"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0c3d8b12db378aef\/66bfa6ff00dce9104efb4c23\/Pixel_3-dennizn-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A defunct yet unremovable application embedded in the firmware of all Google Pixel phones can function as a perfect malicious backdoor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Showcase.apk&#8221; was designed by Pittsburgh-based Smith Micro, specifically for Pixel devices on display at Verizon stores. Somehow, some way, it ended up <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/mobile-security\/malware-pre-installed-on-over-two-dozen-android-smartphone-brands\" rel=\"noopener\">pre-installed in every Pixel phone<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> shipped since at least September 2017 \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/threat-actor-millions-pre-infected-android-phones-cybercrime-enterprise\" rel=\"noopener\">millions around the globe<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, across every model besides the very first, even in those not serviced by Verizon. Dark Reading has reached out to Verizon for information on how this happened.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s bad news, iVerify noted in a report yesterday, as the app possesses significant privileges, and the capability to perform <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/iverify.io\/blog\/iverify-discovers-android-vulnerability-impacting-millions-of-pixel-devices-around-the-world\" rel=\"noopener\">all kinds of malicious functions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. And because it exists in the base image of the phone, there&#8217;s no way for anyone but Google itself to get rid of it.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Showcase.apk Is Not A-OK\">Showcase.apk Is Not A-OK<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Earlier this year, iVerify identified an insecurity in an Android device used by Palantir Technologies, the big data company which contracts with government intelligence and defense agencies. Their investigation led to showcase.apk, a now obsolete Android Package File (APK) contracted by Verizon Wireless for use in its demo devices.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There were many elements of this app which remain shrouded in mystery to this day, such as why it was installed on anything besides the phones displayed in Verizon stores and why it was it so unduly privileged. The app inherits &#8220;excessive&#8221; system-like privileges for no discernible reason. It can use those privileges to run commands in a shell environment, or install arbitrary packages, among other things.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;You can use your imagination for how it could be used,&#8221; says Rocky Cole, Co-Founder &amp; COO at iVerify, himself a former Google employee. &#8220;It has the ability to control the device \u2014 like, turn the camera on and off, read text messages, emails, as part of its core demo store functionality.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It doesn&#8217;t help, then, that the package is riddled with vulnerabilities. It communicates with a command-and-control (C2) domain and downloads files over unsecure HTTP, opening the door to man-in-the-middle (MITM) attacks, the insecure certificate and signature verification processes it uses to check incoming files can return valid responses even after failure, and more.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Silver Lining\">A Silver Lining<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There are two bits of good news, though.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For one thing, showcase.apk appears to be off by default. And, it turned out, iVerify researchers could only toggle it on when they had physical proximity to a targeted device (through mechanisms they would not disclose prior to any Google patch).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The assumption that proximity to the device is required to activate it is truly the only thing standing between the adversary and the end user,&#8221; explains Cole who, besides Google, also formerly worked as an NSA analyst. &#8220;If you overcome that barrier \u2014 and I can think of a few ways that you might \u2014 what you essentially have is an undetectable, persistent spiral.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This would be of most concern to high-risk users. &#8220;At Palantir, for example, a lot of their customers work in really contested spaces. They&#8217;re on the front lines of not just digital conflict, but actual, kinetic, real world conflict. And a lot of national security capabilities are built on Android. And so this vulnerability would be the perfect second or third stage of a mobile exploit chain,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As an example of where showcase.apk could fit into a wider attack chain, he points to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/operation-triangulation-spyware-attackers-bypass-iphone-memory-protections\" rel=\"noopener\">Operation Triangulation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;The exploit chain on that was 10 or 12 steps long \u2014 think about showcase.apk as fitting somewhere in the middle to the end of that.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Not Planned for Google Pixel 9\">Not Planned for Google Pixel 9<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thus far, no evidence suggests that showcase.apk has been exploited in the wild.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In statements to the press, Google spokespeople have indicated that the upcoming Google Pixel 9 will not include the package at all. For existing Pixels, Google is reportedly <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.wired.com\/story\/google-android-pixel-showcase-vulnerability\/\" rel=\"noopener\">working on an update<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to be released &#8220;in the coming weeks.&#8221; Until then, Pixel owners at high risk can do little more than protect their phones physically, to make difficult the initial methods of intrusion which pave the way for showcase.apk abuse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dark Reading has reached out to Google for more information about any upcoming fixes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And to Cole, there&#8217;s a broader issue at play. &#8220;Take CrowdStrike: It&#8217;s wittingly placed there by the end user. If you buy CrowdStrike, you agree to have third-party software running at the kernel level on your machines. What&#8217;s different about Showcase.apk is that no end user ever gets the [option] other than to just accept Pixel&#8217;s Terms of Service. It&#8217;s a take it or leave it proposition \u2014 you either accept the bloatware or you don&#8217;t use Pixel,&#8221; he explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The lesson here,&#8221; he concludes, &#8220;is it&#8217;s probably risky to push third-party software so deep in the operating system without giving users the ability to remove it.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/remote-workforce\/every-google-pixel-phone-has-a-verizon-app-backdoor\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A defunct yet unremovable application embedded in the firmware of<\/p>\n","protected":false},"author":12,"featured_media":4934,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4933","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/every-google-pixel-phone-has-a-verizon-app-that-doubles-as-a-backdoor-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4933"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4933\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4934"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4933"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}