Long-running major vulnerability left millions of Android handsets wide open to data theft

In this article (5)
Google, in a statement, says that Android users were protected through the Google Play Store Protect feature, and through actions taken by manufacturers. Google stated that this exploit did not impact any apps downloaded from the Play Store.
The scary thing is that this vulnerability apparently has been around for years. Samsung even brings this up in its statement made which says, “Samsung takes the security of Galaxy devices seriously. We have issued security patches since 2016 upon being made aware of the issue, and there have been no known security incidents regarding this potential vulnerability. We always recommend that users keep their devices up-to-date with the latest software updates.”
Questions & Answers
Q.What is the primary risk to users from these leaked signing keys?
What is the primary risk to users from these leaked signing keys?
A bad actor controlling these keys could have Android trust malware-laden apps at the system level. This means any data on vulnerable devices could be at risk, as the device would approve malicious software.
Q.What actions have manufacturers and Google taken to address this vulnerability?
What actions have manufacturers and Google taken to address this vulnerability?
OEM partners promptly implemented mitigation measures. Google implemented broad detections for malware in its Build Test Suite and Play Protect system, and recommends companies swap keys and investigate leaks. Users are advised to update their Android version.
Q.Is it safe to download apps from the Google Play Store after this vulnerability was discovered?
Is it safe to download apps from the Google Play Store after this vulnerability was discovered?
Yes, Google stated that this exploit did not impact any apps downloaded from the Play Store. Google Play Protect also detects the malware, and there is no indication it was on the Play Store.
Q.How long has this vulnerability been present in Android devices?
How long has this vulnerability been present in Android devices?
This vulnerability has apparently been around for years. Samsung has issued security patches since 2016 after being made aware of the issue, indicating its long-standing nature.
Reader pulse
How will this impact Android sales?
22,345 votes so far