| This thread leaves a lot of unanswered questions: 1. This was likely mitigated through a device update. What version did it roll out with? Which devices are still unpatched? 2. How was it compromised? Was it an OEM? An internal leak at Google? 3. What is the attack vector? It sounds like it was likely side-loading apps used by some attacker, but did any of these make it onto the Play Store? |
2. Unknown. Could be multiple independent hacks of the OEM or an ODM, could be an insider, etc.
3. The attack vector is usually sideloading.