Advertisement
Sections
New Android bug allowed hackers to plant malware through NFC beaming
The bug impacted all Android 8 Oreo and older devices that had NFC beaming support.

A bug that was found to have impacted all Android 8 Oreo and later devices allowed hackers to spread malware to nearby phones using NFC beaming. The bug was patched in October 2019.NFC beaming aka Android Beam in Android, allows Android devices to send data like videos, images, files, and apps to a nearby device using Near-Field Communication radio waves, an alternative to Bluetooth or WiFi.Usually, when NFC beaming is used to send an APK file, it is saved on disk and the user is notified whenever a transfer is made. A notification asks the user if they will allow the installation of an app from an unknown sender.[caption id="attachment_6589311" align="alignnone" width="1024"]
The Google Pixel 3a XL. Image: Omkar G[/caption]However, as was recently discovered by a security researcher, a bug kept the NFC beaming feature from notifying users about installing an app from an unknown sender. This is a matter of grave concern as an attacker could, theoretically, beam an app over to your phone and then install a malicious app, compromising it remotely.While the October security update for Android patches the bug, a compromised device is likely to remain compromised because the malicious apps would already have been installed.
How to protect your device from the NFC bug?
On most of the newly-sold Android devices, NFC is enabled by default. In order to disable NFC, you can head to Settings > Connectivity > NFC and Payment. However, in case you use your Android device as an access card, or for contactless payment, you can just disable Android Beam from your settings and leave the NFC and Payment option enabled. This will continue to allow you to use your device for contactless payment but will block NFC file beaming.
Advertisement
First Published:Nov 04, 2019, 12:22:56 IST
Advertisement
Advertisement

Why AI notetakers are raising serious privacy and security concerns
AI notetakers promise effortless meeting summaries, but experts warn they could expose confidential conversations, corporate secrets and personal voiceprints. As businesses increasingly adopt AI-powered meeting assistants, questions over data storage, privacy, consent and legal risks are becoming impossible to ignore
5 min read
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
As Chinese firms continue to improve performance while keeping prices low, the AI race is no longer just about building the smartest model—it is increasingly becoming a battle over who can deliver the best value
2 min read
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
How did Instagram run ads promoting child abuse in India?
India has issued a notice to Meta after an investigation alleged that Instagram displayed paid advertisements promoting child sexual abuse material. MeitY ordered Meta to remove such Instagram ads and explain within seven days how they were approved
8 min read
Why has India halted WhatsApp’s username feature before launch?
India has halted WhatsApp’s planned username feature, citing concerns about cybercrime, impersonation, and law enforcement challenges. As Meta races to address security concerns, here’s why MeitY has paused the rollout, what the feature does, and how it could influence privacy and online safety in India
3 min read
Advertisement
Advertisement
