IBM Exposes Critical Dropbox Android Vulnerability

Posted by red5 on Mar 11, 2015 3:52 PM EDT
eSecurityPlanet; By Sean Michael Kerner
Mail this story
Print this story

The flaw, now identified as CVE-2014-8889, was found inside the Dropbox SDK (software development kit) for Android and could have potentially enabled an attacker to insert an arbitrary access token, to give the attacker access to user information.

IBM built a proof-of-concept exploit that it calls "DroppedIn" to test the impact of the vulnerability. Using the exploit, IBM found that 76 percent of the apps that it analyzed that leverage the Dropbox SDK were at risk from the flaw.

Full Story

  Nav
» Read more about: Story Type: News Story, Security; Groups: Android

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.