Parental Control App For Android Riddled With Vulnerabilities

Vulnerabilities initially found back in 2022 in a parental control Android App by Kiddowares, which has over 5M downloads from the Google Play store, are still causing problems today. Despite an update made by the app maker to address the initial vulnerabilities, not every user has updated to the most recent version of the app, thereby making themselves still vulnerable. Bleeping Computer has additional details:

Researchers at SEC Consult have found that the Kids Place app versions 3.8.49 and older are vulnerable to five flaws that could impact the safety and privacy of its users.

The five security issues are the following:

  1. User registration and login actions return the unsalted MD5 hash of the password, which can be intercepted and easily decrypted. MD5 hashes are no longer considered cryptographically secure, as they can be brute-forced using modern computers.
  2. The customizable name of the child’s device can be manipulated to trigger an XSS payload in the parent web dashboard. Children or attackers can inject malicious scripts to execute on the parent’s dashboard, achieving unauthorized access. The issue has received the identifier CVE-2023-29079.
  3. All requests in the web dashboard are vulnerable to cross-site request forgery (CSRF) attacks. The attack requires knowledge of the device ID, which is obtainable from the browser history. The issue has received the identifier CVE-2023-29078.
  4. An attacker could exploit the app’s dashboard feature, originally intended for parents to send files up to 10MB to their child’s device, to upload arbitrary files to an AWS S3 bucket. This process generates a download URL which is then sent to the child’s device. No antivirus scan takes place on the uploaded files, so these can contain malware.
  5. The app user (child) can temporarily remove all usage restrictions to bypass parental controls. Exploiting the flaw, tracked as CVE-2023-28153, does not generate a notification to the parent, so it goes unnoticed unless a manual check is performed on the dashboard.

SEC Consult’s report contains proof-of-concept requests or step-by-step instructions on exploiting the above issues, making it easy for threat actors to exploit the vulnerabilities on older versions of the apps or for children to bypass restrictions.

Therefore, it is essential to update to a secure version of the app, which is 3.8.50 or later.

The analysts discovered the flaws on November 23, 2022, while testing Kids Place 3.8.45 and reported it to the vendor, Kiddoware.

The vendor eventually addressed all problems with version 3.8.50, released on February 14, 2023.

App users can update to the latest version by opening the Google Play store, tapping their account icon, selecting ‘Manage apps & device,’ and tapping on ‘Check for updates.’

Chris Roeckl, chief product officer at mobile app security company Appdome, says:

“Technically speaking, the user is not in the best position to protect themselves or their devices. The level of sophistication of malware and synthetic fraud tools has outpaced the user’s ability to self-protect themselves. What this means is that the burden and responsibility have shifted to the app publisher/developer to protect the user. The journey to protect the user has to be the focus of app developers from here on out.

If the app market had used in-app security protections, including data encryption, anti-malware, anti-fraud and app code protections, this situation, and others like it, could have been avoided. Using a code-less automated cyber defense system to add these protections allows developers to get protections like these released rapidly, within the software engineering pipeline.”

So if you use this app, you should update right away. But I will also say that the makers of that app need to do better to make sure that their app is secure.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading