CVE-2017-13156 in Android Allows Bypass App Signatures
A serious vulnerability (CVE 2017 13156) in Android allows attackers to modify the code in applications without affecting their signatures. The root of the problem is that a file can be a valid APK file and a valid DEX file at the same time. Discovered by the research team at mobile security firm GuardSquare, they named it the Janus vulnerability, after the Roman god of duality.
What is Janus…
View On WordPress















