Several Android applications have been seen to transfer app data from one device to another without invalidating or revalidating session cookies.
According to a new advisory from CloudSEK researchers, the method would allow attackers with a highly privileged device migration tool to migrate programmes to a new Android device, leading to migration problems.
This implies that if someone has physical access to your unlocked device for a while, they can copy your app data onto their device and use the programs on your behalf without entering a login ID or password, according to a statement from the firm read Android Apps Fail to Protect User Data During Device Transfer.
With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.
