In Blackhat 2015, Mobile security team of Alibaba has disclosed many 
serious Android app signature verification vulnerabilities. Detail can be 
found in link 
https://www.blackhat.com/docs/ldn-15/materials/london-15-Xiao-What-Can-You-Do-To-An-APK-Without-Its-Private-Key-wp.pdf
This PDF report discusses vulnerabilities, exploitation and mitigation. 

I did not find anything in PDF report or in web search about Google's 
response on these vulnerabilities. Does anyone know if Google has 
officially acknowledged issues and is planning fixes, did they give any 
timeline or something?

-- 
You received this message because you are subscribed to the Google Groups 
"Android Security Discussions" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at http://groups.google.com/group/android-security-discuss.
For more options, visit https://groups.google.com/d/optout.

Reply via email to