Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Popular Android remote app AirDroid is vulnerable to hacks

Add as a preferred source on Google

If you’re an Android user, you may have heard of AirDroid, a souped-up remote control app that lets you wirelessly connect to an Android phone or tablet. It’s impressively robust: you can respond to text messages directly from your PC, dismiss or answer an incoming call, silence notifications from certain apps, and even transfer files and photos simply by clicking and dragging. But it’s also frighteningly vulnerable to hacks: according to research firm Zimperium, a nasty security hole has left “tens of millions” of AirDroid’s users susceptible to data-stealing attackers.

At fault is the app’s weak method of encryption. In a blog post published Friday, Zimperium reported that AirDroid’s key — a digital passcode made up of a combination of numbers, letters, and characters — that it uses to obfuscate sensitive updates and data is both “static” and “easily detectable.” And while AirDroid uses the industry-standard HTTPS security protocol to handle most files, the app transfers crucial bits over unencrypted HTTP.

Recommended Videos

That opens the door for a reasonably skilled hacker to perform what’s known as a man-in-the-middle attack: using a third-party computer to impersonate AirDroid’s servers, deliver fraudulent app updates, and view sensitive information. In this manner, hackers could steal email addresses and passwords, surreptitiously install apps, or even replace the legitimate AirDroid application with a malicious replica.

“A malicious party on the same network as the victim can leverage this vulnerability to take full control of their device,” Simone Margaritelli, Zimperium’s principle security researcher, told Ars Techica. “Moreover, the attacker will be able to see the user’s sensitive information … As soon as the update, or fake update, is installed the software automatically launches the updated [Android app file] without ever verifying who built it.”

Zimperium disclosed the vulnerability to AirDroid in May, but it remains present in the newest major release of AirDroid — version 4 — launched in mid-November. A subsequent patch, version 4.0.0.1, doesn’t appear to have addressed the flaw. And San Studios, the development team behind AirDroid, has yet to respond to Zimperium’s accusations.

In a statement published to the official AirDroid blog, Sand Studio said it hoped to have a fix ready within two weeks.

If you’re an active AirDroid user, your options are relatively few.

Android limits the extent to which malicious apps can modify your phone’s files, but AirDroid has more access than most. It can make app purchases, and can access contacts, text messages, device location, camera, microphone, photos, Wi-Fi connection data, device ID, and call information. And a malicious update posing as a legitimate one could request additional permissions.

A virtual private network, or VPN, is a potential — but imperfect — solution. VPNs add a layer of security to unencrypted networks, providing a measure of protection from attackers. Ars Technica notes, though, there’s no guarantee a hacker won’t work around it by employing a captive portal — the sort of web page that hotels and airlines use to collect payment and registration information — to kick a VPN user to a compromised connection.

Until the problem’s patched, you’re best off using AirDroid only on wireless networks that you know and trust. If you rely on public Wi-Fi, though, you’re safest disabling or uninstalling AirDroid until a patch is in place.

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Samsung’s upcoming Galaxy Z Flip 8 foldable might disappoint with its battery situation
The foldable could bring small changes elsewhere, but battery convenience may remain a weak spot
Samsung Galaxy Z Flip 4.

Samsung's next flip-style foldable is shaping up as a careful update, which isn't great news for anyone hoping the company would finally tackle one of the line's most obvious weak spots. The latest leak points to the Galaxy Z Flip 8 sticking with 25W wired charging, a familiar limit that risks making the phone feel too safe in daily use.

That tradeoff has followed the Flip series for years. Samsung has sold the appeal of a compact foldable design well, but buyers have often had to accept a few practical compromises in return, and battery convenience has stayed near the top of that list.

Read more
Amazon Kindle Scribe Colorsoft review: The luxury ride to digital note-taking
It wants to be your indispensable digital diary, but it will test your Kindle loyalty, too.
Amazon Kindle Scribe

Quick Take

The Kindle Scribe Colorsoft is a new breed of e-readers from Amazon. Aside from being your reading companion, it also wants to double as your trusty note-taking device. And it does a terrific job at serving as a digital diary. The color display does a fine job of replicating the sensation of writing on paper, without any of the input lag woes you would notice on an ordinary tablet. 

Read more
Apple’s foldable is keeping Camera Control, but one-handed photography on a big foldable sounds tricky
Apple went through some serious engineering gymnastics to make it happen, but is it worth it?
Electronics, Mobile Phone, Phone

Apple's first foldable iPhone has been the subject of countless leaks, and the latest one comes from Weibo leaker Instant Digital. As reported by Notebookcheck, the leak suggests that the iPhone Fold will include the Camera Control button, despite being thinner than the iPhone Air when unfolded.

That's no small feat. Fitting the Camera Control button into a device that slim must have required some serious engineering work on Apple's part. But apparently, Apple felt it was worth it.

Read more