y0news
AnalyticsDigestsSourcesTopicsRSSAICrypto

#mobile-security News & Analysis

13 articles tagged with #mobile-security. AI-curated summaries with sentiment analysis and key takeaways from 50+ sources.

13 articles
CryptoBearishBlockonomi · Apr 117/10
⛓️

EngageLab Flaw Opened 30M Wallet Apps to Android Data Theft: Microsoft

Microsoft discovered a critical vulnerability in the EngageLab SDK that exposed private wallet data across 30 million Android installations. The flaw allowed malicious applications to gain unauthorized read and write access to sensitive user information through Android intents, posing significant risks to cryptocurrency wallet users globally.

CryptoBearishDaily Hodl · 3d ago7/10
⛓️

Malware Targets 180 Banking, Financial and Crypto Apps, Displays Fake Screens To Capture PINs and Take Over Accounts: Cyble

Cyble has identified OverlayPhantom, a new Android banking trojan targeting over 180 banking, financial, and cryptocurrency applications across 10 countries. The malware uses fake overlay screens to capture PINs and credentials, enabling account takeover through a two-stage infection chain distributed via malicious URLs impersonating legitimate apps.

Malware Targets 180 Banking, Financial and Crypto Apps, Displays Fake Screens To Capture PINs and Take Over Accounts: Cyble
AIBearisharXiv – CS AI · May 287/10
🧠

MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content

Researchers demonstrate MIRAGE, a technique that exploits vision-language model vulnerabilities in mobile GUI agents by injecting adversarial text into user-generated content regions. The attack achieves 23-30% success rates across five VLM agents without modifying apps or operating systems, revealing a critical security gap in AI-powered mobile automation that existing visual-quality defenses cannot reliably prevent.

CryptoBearishcrypto.news · May 87/10
⛓️

Mobile wallet zero‑days put SDKs under fire – and highlight the case for isolation

Mobile wallet zero-day vulnerabilities and SDK flaws are eroding user confidence in centralized cryptocurrency solutions, prompting advanced users to adopt isolated, multi-device signing architectures that limit exposure from single-point compromises. The trend underscores systemic risks in third-party software dependencies that retail users often fail to recognize.

Mobile wallet zero‑days put SDKs under fire – and highlight the case for isolation
CryptoBearishCoinTelegraph · Mar 127/10
⛓️

MediaTek patches bug enabling crypto seed theft in just 45 seconds

Ledger's security team discovered a critical vulnerability in MediaTek's secure boot chain that allows attackers to steal cryptocurrency seed phrases from Android devices in just 45 seconds. MediaTek has since patched the security flaw that could have compromised sensitive crypto wallet information on affected Android devices.

MediaTek patches bug enabling crypto seed theft in just 45 seconds
CryptoBearishDecrypt – AI · Mar 117/10
⛓️

Android Phone Crypto Wallets Could Be at Risk Due to MediaTek Exploit: Ledger

A security vulnerability in MediaTek-powered Android phones could allow attackers to extract encrypted data, including cryptocurrency wallet seed phrases, through a USB connection. This security flaw poses significant risks to crypto users who store wallet data on affected devices.

Android Phone Crypto Wallets Could Be at Risk Due to MediaTek Exploit: Ledger
CryptoBearishThe Defiant · Mar 117/10
⛓️

Ledger Uncovers Security Vulnerability That Could Affect 25% of Android Phones

Ledger has discovered a chip vulnerability affecting 25% of Android smartphones that enables hackers to decrypt devices and steal sensitive data, including cryptocurrency wallet private keys. This security flaw poses significant risks to crypto holders who store their digital assets on affected Android devices.

Ledger Uncovers Security Vulnerability That Could Affect 25% of Android Phones
CryptoBearishBeInCrypto · Mar 57/10
⛓️

iPhone Crypto Wallets at Risk as Google Detects New iOS Exploit Kit

Google discovered a new iOS exploit kit called Coruna that silently infiltrates iPhones through compromised websites to steal cryptocurrency from popular wallet apps including MetaMask, Phantom, and Trust Wallet. The attack requires no user interaction beyond visiting a malicious website on an unpatched iPhone device.

iPhone Crypto Wallets at Risk as Google Detects New iOS Exploit Kit
CryptoBearishCoinTelegraph · Mar 57/10
⛓️

Google warns of crypto scams using ‘new and powerful’ iPhone exploit kit

Google threat researchers discovered fake cryptocurrency websites hosting a new exploit kit capable of compromising iPhones to steal crypto assets. The sophisticated attack targets iOS devices specifically to hunt for and extract cryptocurrency holdings from victims.

Google warns of crypto scams using ‘new and powerful’ iPhone exploit kit
AIBearisharXiv – CS AI · Mar 47/104
🧠

Zero-Permission Manipulation: Can We Trust Large Multimodal Model Powered GUI Agents?

Researchers discovered a critical security vulnerability in AI-powered GUI agents on Android, where malicious apps can hijack agent actions without requiring dangerous permissions. The 'Action Rebinding' attack exploits timing gaps between AI observation and action, achieving 100% success rates in tests across six popular Android GUI agents.

AINeutralarXiv – CS AI · Apr 146/10
🧠

Turing Test on Screen: A Benchmark for Mobile GUI Agent Humanization

Researchers introduce the 'Turing Test on Screen,' a framework for measuring how well autonomous GUI agents can mimic human behavior to evade detection systems. The study reveals that current LLM-based agents exhibit unnatural interaction patterns and proposes humanization methods to improve their ability to operate undetected in adversarial digital environments.

AINeutralArs Technica – AI · 1d ago5/10
🧠

Android phones will soon be able to detect spoofed calls and impersonation scams

Google's June Android feature drop introduces enhanced scam detection capabilities, enabling Android phones to identify spoofed calls and impersonation attempts. The update reflects growing industry focus on protecting users from phone-based fraud through on-device AI technology.

Android phones will soon be able to detect spoofed calls and impersonation scams