Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Leica can now style your iPhone photos to mimic a pro photographer

    May 15, 2025

    This modern cassette boombox will lure you in with glowing VU meters

    May 15, 2025

    How Mexico’s Fishing Refuges Are Fighting Back Against Poaching

    May 14, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Nearly All Google Pixel Phones Exposed by Unpatched Flaw in Hidden Android App
    Security

    Nearly All Google Pixel Phones Exposed by Unpatched Flaw in Hidden Android App

    News RoomBy News RoomAugust 19, 20243 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    Google’s flagship Pixel smartphone line touts security as a centerpiece feature, offering guaranteed software updates for seven years and running stock Android that’s meant to be free of third-party add-ons and bloatware. On Thursday, though, researchers from the mobile device security firm iVerify are publishing findings on an Android vulnerability that seems to have been present in every Android release for Pixel since September 2017 and could expose the devices to manipulation and takeover.

    The issue relates to a software package called “Showcase.apk” that runs at the system level and lurks invisible to users. The application was developed by the enterprise software company Smith Micro for Verizon as a mechanism for putting phones into a retail store demo mode—it is not Google software. Yet for years, it has been in each Android release for Pixel and has deep system privileges, including remote code execution and remote software installation. Even riskier, the application is designed to download a configuration file over an unencrypted HTTP web connection that iVerify researchers say could be hijacked by an attacker to take control of the application and then the entire victim device.

    iVerify disclosed its findings to Google at the beginning of May, and the tech giant has not yet released a fix for the issue. Google spokesperson Ed Fernandez tells WIRED in a statement that Showcase “is no longer being used” by Verizon, and Android will remove Showcase from all supported Pixel devices with a software update “in the coming weeks.” He added that Google has not seen evidence of active exploitation and that the app is not present in the new Pixel 9 series devices that Google announced this week.

    In response to WIRED’s inquiry about Showcase’s vulnerability, Verizon spokesperson George Koroneos says, “The APK in question was used for retail demos and is no longer in use.” Smith Micro said in a statement that, “The APK in question was previously licensed to Verizon for in-store retail demos, and is no longer in use.”

    “I’ve seen a lot of Android vulnerabilities, and this one is unique in a few ways and quite troubling,” says Rocky Cole, chief operating officer of iVerify and a former US National Security Agency analyst. “When Showcase.apk runs, it has the ability to take over the phone. But the code is, frankly, shoddy. It raises questions about why third-party software that runs with such high privileges so deep in the operating system was not tested more deeply. It seems to me that Google has been pushing bloatware to Pixel devices around the world.”

    iVerify researchers discovered the application after the company’s threat-detection scanner flagged an unusual Google Play Store app validation on a user’s device. The customer, big data analytics company Palantir, worked with iVerify to investigate Showcase.apk and disclose the findings to Google. Palantir chief information security officer Dane Stuckey says that the discovery and what he describes as Google’s slow, opaque response has prompted Palantir to phase out not just Pixel phones, but all Android devices across the company.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleCatan: New Energies Is Caught in a Climate Crisis
    Next Article The Best Projectors for Your Home Movie Nights

    Related Posts

    Google’s Advanced Protection for Vulnerable Users Comes to Android

    May 14, 2025

    Google Is Using On-Device AI to Spot Scam Texts and Investment Fraud

    May 14, 2025

    An $8.4 Billion Chinese Hub for Crypto Crime Is Incorporated in Colorado

    May 14, 2025

    ICE’s Deportation Airline Hack Reveals Man ‘Disappeared’ to El Salvador

    May 13, 2025

    US Border Agents Are Asking for Help Taking Photos of Everyone Entering the Country by Car

    May 13, 2025

    The Trump Administration Sure Is Having Trouble Keeping Its Comms Private

    May 12, 2025
    Our Picks

    This modern cassette boombox will lure you in with glowing VU meters

    May 15, 2025

    How Mexico’s Fishing Refuges Are Fighting Back Against Poaching

    May 14, 2025

    SoundCloud changes its TOS again after an AI uproar

    May 14, 2025

    Apple Maps will show recommendations from Michelin and The Infatuation

    May 14, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Science

    Why Pigeons at Rest Are at the Center of Complexity Theory

    By News RoomMay 14, 2025

    By January 2020, Papadimitriou had been thinking about the pigeonhole principle for 30 years. So…

    Apple might let you scroll with your eyes in the Vision Pro

    May 14, 2025

    Brian Chesky Lost His Mind One Night—and Now He’s Relaunching Airbnb as an Everything App

    May 14, 2025

    Grok really wanted people to know that claims of white genocide in South Africa are highly contentious

    May 14, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.