{"id":180876,"date":"2021-02-17T21:45:42","date_gmt":"2021-02-17T18:45:42","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/uninstall-the-shareit-android-app-now-to-avoid-critical-vulnerabilities-review-geek\/"},"modified":"2021-02-17T21:45:42","modified_gmt":"2021-02-17T18:45:42","slug":"uninstall-the-shareit-android-app-now-to-avoid-critical-vulnerabilities-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/uninstall-the-shareit-android-app-now-to-avoid-critical-vulnerabilities-review-geek\/","title":{"rendered":"#Uninstall the ShareIt Android App Now to Avoid Critical Vulnerabilities \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#Uninstall the ShareIt Android <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a> Now to Avoid Critical Vulnerabilities \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1599px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71328 size-full\" src=\"https:\/\/www.reviewgeek.com\/thumbcache\/0\/0\/13275b67cf83d2d3eb4b51ddd19c6223\/p\/uploads\/2021\/02\/xb945b441.png.pagespeed.gp+jp+jw+pj+ws+js+rj+rp+rw+ri+cp+md.ic.McIPc0kcKG.jpg\" alt=\"A graphic of the ShareIt app with a game store open.\" width=\"1599\" height=\"1007\" data-credittext=\"ShareIt\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"imagecredit\">ShareIt<\/span><\/figcaption><\/figure>\n<p><span data-preserver-spaces=\"true\">Do you have the popular Android app <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.lenovo.anyshare.gps&amp;hl=en_US&amp;gl=US\">ShareIt<\/a> installed on your phone? You should uninstall that as soon as possible. Sooner if possible. According to researchers at <a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/redirect.viglink.com?u=https%3A%2F%2Fwww.trendmicro.com%2Fen_us%2Fresearch%2F21%2Fb%2Fshareit-flaw-could-lead-to-remote-code-execution.html%3FPID%3D100017430%26amp%3BSID%3D100098X1555750X8ba3a51ee587c02b971909e9cfc15936%26amp%3Bcjevent%3Dbb4a3528714511eb815c00aa0a240611&amp;key=204a528a336ede4177fff0d84a044482\">Trend Micro<\/a>, ShareIt suffers from many fatal flaws that could let hackers execute code on your device, install malicious apps, and more. And after three months, ShareIt chose to do nothing about the problem.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">According to Trend Micro, the vulnerabilities would allow bad actors to \u201cleak a user\u2019s sensitive data and execute arbitrary code with ShareIt permissions.\u201d ShareIt comes with extensive permissions requirements due to being an \u201ceverything in one\u201d app. <\/span><\/p>\n<p><span data-preserver-spaces=\"true\">As the name suggests, it started life as a sharing app, which already calls for plenty of permissions needs. But the app ballooned, and now it\u2019s a gif app, a video player, a song finder, a <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/game\/\" data-internallinksmanager029f6b8e52c=\"7\" title=\"Game\" target=\"_blank\" rel=\"noopener\">game<\/a> store, a movie store, and more.\u00a0<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">ShareIt can request access to the camera, microphone, location, the entire user storage, and all <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>. But while it requests all those permissions, it fails to put in the proper restrictions Android calls for to prevent abuse.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">The problem stems from how the developers enabled external storage permissions. If developers follow proper guidelines, everything will be fine. But ignore them, as ShareIt\u2019s developers did, and you\u2019ll leave your users vulnerable to a \u201c<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.checkpoint.com\/2018\/08\/12\/man-in-the-disk-a-new-attack-surface-for-android-apps\/\">man-in-the-disk<\/a>\u201d attack.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Apps install files should be sent to protected storage to keep them safe during the critical install period. If the developer stores those files in public storage instead, a bad actor can intercept the install files, replace them with new versions, and essentially upgrade an app to a malicious app. The same thing happened with Epic\u2019s Fortnite installer in 2018.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">If that\u2019s not bad enough, ShareIt\u2019s game store downloads app data over unsecured network connections (HTTP), which leaves the app open to\u00a0<\/span><a rel=\"nofollow noopener\" target=\"_blank\" class=\"editor-rtfLink\" href=\"https:\/\/www.howtogeek.com\/668989\/what-is-a-man-in-the-middle-attack\/\"><span data-preserver-spaces=\"true\">man-in-the-middle attacks<\/span><\/a><span data-preserver-spaces=\"true\">. With the right know-how, a bad actor can update ShareIt to a malicious version, steal your user data, or both.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Trend Micro says it notified ShareIt\u2019s developers three months ago about the problems and never heard back. Hopefully, all the bad publicity will help change the course, but in the meantime, you\u2019d be better off uninstalling ShareIt, at least for now.<\/span><\/p>\n<p><small>Source: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/redirect.viglink.com?u=https%3A%2F%2Fwww.trendmicro.com%2Fen_us%2Fresearch%2F21%2Fb%2Fshareit-flaw-could-lead-to-remote-code-execution.html%3FPID%3D100017430%26amp%3BSID%3D100098X1555750X8ba3a51ee587c02b971909e9cfc15936%26amp%3Bcjevent%3Dbb4a3528714511eb815c00aa0a240611&amp;key=204a528a336ede4177fff0d84a044482\">Trend Micro<\/a> via <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/02\/shareit-android-app-with-over-a-billion-downloads-is-a-security-nightmare\/\">Ars Technica<\/a><\/small>\n<\/div>\n<p><script>setTimeout(function(){!function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod?n.callMethod.apply(n,arguments):n.queue.push(arguments)};if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0;t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,document,'script','https:\/\/connect.facebook.net\/en_US\/fbevents.js');fbq('init','1137093656460433');fbq('track','PageView');},3000);<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/71318\/uninstall-the-shareit-android-app-now-to-avoid-critical-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Uninstall the ShareIt Android App Now to Avoid Critical Vulnerabilities \u2013 Review Geek&#8221; ShareIt Do you have the popular Android app ShareIt installed on your phone? You should uninstall that as soon as possible. Sooner if possible. According to researchers at Trend Micro, ShareIt suffers from many fatal flaws that could let hackers execute code&#8230;<\/p>\n","protected":false},"author":1,"featured_media":180877,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/thumbcache\/0\/0\/13275b67cf83d2d3eb4b51ddd19c6223\/p\/uploads\/2021\/02\/xb945b441.png.pagespeed.gp+jp+jw+pj+ws+js+rj+rp+rw+ri+cp+md.ic.McIPc0kcKG.jpg","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-180876","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/180876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=180876"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/180876\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/180877"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=180876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=180876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=180876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}