Blog
Gaps in Google Play Store XFO Allow Attackers to Remotely Install Malware on Android Devices
By David Bisson on Thu, 02/12/2015
Attackers can use gaps in the X-Frame Options (XFO) support on Google’s Play Store web application to remotely install malware onto users’ Android devices. “A malicious user can leverage either a Cross-Site Scripting (XSS) vulnerability in a particular area of the Google Play Store web application, or a Universal XSS (UXSS) targeting affected...