A small bug in the signature verification of AOSP OTA packages
blog.quarkslab.com | research | #android | #vulnerability | #aosp | #ota | #signature-verification | #zip
Summary
Quarkslab finds a small but critical bug in AOSP's OTA package signature verification — a bypass in RecoverySystem.verifyPackage, which checks the integrity of update ZIP archives.
- Published
- Collected
Skip to content