IBM Exposes Critical Dropbox Android Vulnerability
The flaw, now identified as CVE-2014-8889, was found inside the Dropbox SDK (software development kit) for Android and could have potentially enabled an attacker to insert an arbitrary access token, to give the attacker access to user information.
IBM built a proof-of-concept exploit that it calls "DroppedIn" to test the impact of the vulnerability. Using the exploit, IBM found that 76 percent of the apps that it analyzed that leverage the Dropbox SDK were at risk from the flaw.
|
|
Full Story |
This topic does not have any threads posted yet!
You cannot post until you login.