Hacker News new | ask | show | jobs
by scarface74 2154 days ago
I can tell you about an app that you might have heard of that bypassed the Google Play Store and was a security nightmare.

https://www.cnet.com/news/just-as-critics-feared-fortnite-fo...

1 comments

> Fortnite became available for Android on Aug. 9, starting with Samsung Galaxy devices, and then became available for all of Android on Aug. 12. Google brought the vulnerability to Epic Games' attention on Aug. 15. Epic Games immediately acknowledged its mistake and fixed the bug with version 2.1.0 of the launcher on Aug. 16.

Iirc the issue was that they first downloaded a file and then ran it. Thus there was a short window of time where someone can tamper with the file before it's running. Far from being a security nightmare it was a subtle flaw, and fixed quickly.