106
submitted 6 months ago by L4s@lemmy.world to c/technology@lemmy.world

Chameleon Android malware can turn off fingerprint unlock to steal your pin::Be careful out there.

all 20 comments
sorted by: hot top controversial new old
[-] Deebster@programming.dev 31 points 6 months ago

It still needs a gullible user to change their settings for this to work; not much to worry about here.

[-] rush@lemm.ee 0 points 6 months ago* (last edited 6 months ago)

Note that for this attack to work, you have to be on Android 11 or below (or possibly an earlier patch) as by default accessibility services aren't allowed to draw-over or interact with elements in the settings app unless you explicitly override it in developer options.

This extends to some other areas, like for when biometric/system lock APIs are used.

[-] BearOfaTime@lemm.ee 2 points 6 months ago

So you have to enable the "draw over settings", which is pretty deep in settings (developer options).

You kinda deserve it if you do this. Lol

this post was submitted on 25 Dec 2023
106 points (95.7% liked)

Technology

55692 readers
2485 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS