SHAREit


Even with extremely popular applications with an enormous number of downloads, one can by no means be sure that the developers are acting reasonably professionally. This is currently evident, for example, from the SHAREit app for Android .

The manufacturer of the software has not been able to fix a security hole for three months. The vulnerability enables attackers to smuggle code onto an Android smartphone and execute it. This is the result of a bug analysis by the security service provider Trend Micro. The cause of the problem are therefore inadequate restrictions on access to the app's code, which would have to be implemented by the developer.

Malicious code can be smuggled into the app relatively easily. After all, SHAREit is an application that is currently aimed at exchanging content with other devices. Ultimately, it is part of this that the app more or less willingly accepts data from outside - and the responsibility of the developer is correspondingly great to ensure that the incoming information does not become a problem.

SHAREit 

Deletion is the only protection

Here, however, a simple man-in-the-middle attack is more or less enough to smuggle malicious code onto an Android system and execute it. This enables unauthorized persons to destroy the user's data or to abuse it for blackmail using ransomware. Spy tools can also be installed on systems quite easily.

The security experts sent their findings to the app developer three months ago. However, it has not yet been possible to really come into contact with this. There was never an answer. The provider did not provide a bug fix either. With smaller apps, you could probably put things aside, but according to the Play Store statistics, SHAREit has download numbers in the billions and is accordingly widespread. Trend Micro therefore decided to make the findings public and explicitly warn against using the app - until there is a reaction from the developer, it would be better to delete it from Android devices.