Original topic:

Loophole in Secure folder privacy💀💀

(Topic created on: 08-28-2023 10:51 AM)
363 Views
kattuu
Active Level 2
Options
Others
Hi,
recently I found out that airtel app installed in secure folder with given no permissions can access the otp generated outside the secure folder .If it has an access to apps outside my secure folder ,what's the use of secure folder .
I do get it you can hide things from people who use your phone by enabling and keeping things in here but we expect that apps that are inside the folder should not be able to access the apps outside this folder .
Also isn't it dangerous that even if I had given no permission to airtel app ,it was able to access my messaging app .
Huge Security Flaw from SAMSUNG .
0 Likes
4 Comments
owl123
Active Level 10
Others
Apps don't need sms permission for otp. They use google play services for reading the otp sms without the need of sms permission
https://developers.google.com/identity/sms-retriever/overview
0 Likes
kattuu
Active Level 2
Others
Hmm ,let me see this documentation BTW it does not happen with WhatsApp .While you fill up ur phone number and wait for otp while it ask for permissions and u don't give any of those .WhatsApp will not be able to read ur otp automatically .Looks good on WhatsApp side.
BTW Thanks for the documentation page . 🙂
0 Likes
owl123
Active Level 10
Others
I guess it depends on whether developers want to use the api or not. In China for example where phones don't have google play services they have to resort to using sms permission
Anonymous
Not applicable
Others
But the concern reported is valid i guess. Any undetected flaw in this api or apps using the service might affect the security. Chances might be rare.
0 Likes