Skip to main content

Security researchers expose Gmail smartphone hack

security researchers expose gmail smartphone hack big app
Image used with permission by copyright holder
Researchers from the Universities of Michigan and California say they’ve come up with a smartphone hack that can get into your Gmail account via your mobile device. A number of apps are affected by the vulnerability but Gmail was exploited with a 92 percent success rate.

According to the details of the research, the hack — as you might expect — relies on a malware app posing as a genuine bit of software, so you should be safe if you take good care over what’s allowed to run on your handset. Once the malicious code is in place it can use a mobile device’s shared memory to jump into other apps, including Gmail.

Recommended Videos

Related: Gmail acts to sort out new scam using non-Latin characters

“The assumption has always been that these apps can’t interfere with each other easily,” said Zhiyun Qian, one of the team working on the project. “We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user.” Banking apps were also successfully breached using the same method.

The hack relies on being able to predict what the user will do next and timing an interception perfectly, so some apps proved more vulnerable than others. Of the seven apps tested, Gmail was the easiest to access while the Amazon app was the most difficult. The exploit was run on an Android phone though the researchers say the same principles can potentially be applied to iOS and Windows Phone.

Thanks to the procedures put in place to block and root out malware, the vulnerability reported here shouldn’t worry the majority of users. Nevertheless it’s a working demonstration of how a device’s shared memory can be misused, and another reminder to take care with your app installs — particularly if you’re on a rooted device.

A Google spokeswoman welcomed the report: “Third-party research is one of the ways Android is made stronger and more secure,” she said. The findings will be revealed in full at the USENIX Security Symposium in San Diego.

[Header image: Alexander Supertramp / Shutterstock.com]

David Nield
Former Digital Trends Contributor
Dave is a freelance journalist from Manchester in the north-west of England. He's been writing about technology since the…
App subscription fatigue is quickly ruining my smartphone
App Store displayed on an iPhone 14 Pro against a pink background

When I first got an iPhone in 2008, I remember checking out web apps, which were basically websites that I would keep bookmarked on the home screen. Every time I opened them up, they somehow didn’t look like I just launched mobile Safari. Eventually, Apple launched the App Store in July 2008, mostly eliminating the need for antiquated web apps.

Since the App Store opened up, we've gotten to see innovative new apps and games that took our iPhones to a completely new level — showing us what our devices were capable of. I was excited to see and hear about new apps for a variety of things, from task managers to camera replacement apps to photo editors to journals and so much more. Games were also making use of the iPhone’s accelerometer and gyroscope sensors, so it wasn’t just always about touchscreen controls.

Read more
You need to update your iPhone and iPad right now to fix a critical security flaw
iOS's App Library page shown on an iPhone 13 Pro.

This is a friendly -- and important -- reminder to update your iPhone and iPad, if you haven’t already.

Apple this week issued an urgent security update for iPhone and iPad owners to patch a flaw that could allow hackers to take control of the devices.

Read more
How to secure Cash App
data plan

Popular money transfer app Cash App hit the news recently after it transpired a security breach impacting 8.2 million U.S. users had leaked sensitive customer information. Although Cash App insists information such as account access codes and passwords weren't compromised, it's still a good idea to ensure your Cash App account is secure. You can do this in a number of different ways, including setting a pin or using biometrics like your fingerprint or Face ID. Keep reading and we'll show you how to secure Cash App to keep your personal information safe.

Read more