The Cybersecurity and Infrastructure Security Agency (CISA) has warned of a severe Android vulnerability that the Chinese e-commerce app Pinduoduo may have exploited to spy on users.
The vulnerability is a zero-day exploit, meaning the security flaw was exploited before developers could fix it.
CISA’s KEV (Known Exploited Vulnerabilities) catalog notes that the high-severity vulnerability affects Android versions 11, 12, 12L, and 13. The vulnerability reportedly allows attackers to bypass security systems and hijack devices without user interaction, CISA said.
CISA has instructed Federal Civilian Executive Branch (FCEB) agencies to address the vulnerability by May 4. CISA also implored government agencies to patch their personnel’s Macs and iPhones against a different set of zero-day vulnerabilities by May 1. Google issued a set of security updates to patch the vulnerability early in March and suspended the Pinduoduo app from the Play Store later in the same month.
Pinduoduo, a shopping app, is very popular in China, with over 750 million monthly active users. PDD Holdings, the company behind Pinduoduo, has another app called Temu which is among the most downloaded apps on Apple’s App Store.
Exploit Requires No User Interaction
This vulnerability — tracked under the code CVE-2023-20963 — can be exploited without user interaction. This distinguishes it from other common vulnerabilities. In an alert issued on April 13, CISA labeled it as an “Android Framework Privilege Escalation Vulnerability.”
“Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed,” CISA noted.
In early March, Android’s parent company Google said there are indications of this specific vulnerability being used to compromise targets via unauthorized access.
Millions of Devices Affected
Last month, mobile security firm Lookout said at least two malicious versions of the popular Chinese e-commerce app were found on third-party Chinese app stores.
According to Lookout, the maliciously-crafted Android apps allowed cybercriminals “to surreptitiously take control of millions of end-user devices to steal personal data and install malicious apps.”
“Some versions of the Pinduoduo app contained malicious code, which exploited known Android vulnerabilities,” Kaspersky security researcher Igor Golovin told Bloomberg in March. He confirmed that “malicious modules” in the apps breached users’ notifications and files.
Cybercriminals use sophisticated techniques to snare victims, including creating compromised or copycat apps. We’ve seen fake apps pop up on Google’s Play Store and Apple’s App Store recently, including counterfeit versions of Baidu’s Ernie app and fake ChatGPT apps.
It’s crucial that you confirm any app you’re downloading is legitimate and not a knockoff or a Trojan horse for malware. Compromised apps can allow threat actors to access your data, including your finances, and launch convincing social engineering scams.
If you have the Pinduoduo app installed on your device, remove it immediately. Only download apps from official app stores and check that the publisher is the app maker. We recommend using a real-time antivirus scanner that can flag malicious apps and websites.
