Even your smart photo frames aren’t safe from hackers now – experts flag popular Android product is at risk, so here’s how to stay safe

  • Experts flag Uhale devices download malicious software automatically each time it boots up
  • Seventeen security issues discovered across the tested digital picture frame models
  • Major flaws include insecure TrustManager implementations and unsanitized filenames

Security researchers have identified critical risks in Uhale-branded digital picture frames, revealing many devices download malicious software immediately after boot.

Mobile security firm Quokka linked payloads to the Vo1d botnet and Mzmess malware families, based on file structure, endpoints, and delivery patterns.

The exact infection vector remains unclear, but the workflow involves automatic app updates that install harmful JAR or DEX files, which execute every time the device restarts.

Multiple flaws create extensive vulnerabilities

Quokka’s analysis uncovered seventeen security issues across tested devices, with eleven assigned CVE identifiers.

Major flaws include insecure TrustManager implementations that permit man-in-the-middle attacks and unsanitized filenames in update commands, enabling remote installation of arbitrary APKs.

Pre-installed apps also expose unauthenticated file servers on local networks, creating additional security risks.

Many devices shipped rooted, with SELinux disabled and AOSP test-keys, leaving them fully compromised from the start.

WebViews ignored SSL/TLS errors, allowing attackers to inject malicious content, and hardcoded AES keys and outdated libraries further intensified risks, creating potential supply-chain vulnerabilities.

The firm noted how estimating the number affected users is difficult because the devices are marketed under multiple brands – with the Uhale app alone has over 500,000 downloads on Google Play, and thousands of reviews across marketplaces.

ZEASN, the company behind Uhale, has not responded to repeated reports from researchers, leaving security issues unaddressed for months.

Consumers are advised to choose devices from reputable manufacturers which rely on official Android firmware and include Google Play services.

To stay safe, users need to maintain antivirus software for detecting and removing threats.

Users should also employ identity theft protection to safeguard personal information and ensure a firewall is active to prevent unauthorized access.

Regularly monitoring updates and avoiding unverified apps can reduce exposure to these vulnerabilities.

Vigilance, layered protections, and awareness of firmware behavior remain critical for maintaining security in increasingly connected environments.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Trump declares 100 percent tariffs on many drones and all aircraft parts

The United States has already banned future foreign drones from entering the United States unless their companies kiss the ring - as well as...

This school-friendly laptop from HP is $300 off

The HP OmniBook X Flip 2-in-1 converts for tablet or tented use. | Image: The Verge With memory prices still high and showing no signs...

Netflix is closing two game studios

A screenshot of Oxenfree II: Lost Signals from Night School Studio. | Image: Night School / Netflix Netflix plans to shut down two of its...

Microsoft’s Clippy-like Mico character is no longer the face of Copilot

Mico is headed to Learn Live. | Image: Microsoft Microsoft Copilot will no longer show its emotive yellow blob, Mico, when you use the chatbot's...

The fight over Flock and other ALPRs

There are over 120,000 of Flock’s automatic license plate reader (ALPR) cameras installed all over the US. Flock’s cameras, and others like them, use...

‘That is not acceptable’: Judge orders Google to make rival app store installs easier

One month after Epic Games and Google seemingly stopped fighting over the future of Android app distribution, they were back in a San Francisco...

Apple and Epic argue over how much Apple should get from purchases made outside the App Store

In a new filing in its long-running legal dispute with Epic Games, Apple has proposed a structure that would allow it to collect fees...

Samsung reportedly abandons plans to give the Galaxy S27 a variable-aperture camera

Another one bites the dust: Early rumors of the Galaxy S27 reviving Samsung’s variable-aperture camera seem to falling short, as the company is already...

Pixel 11’s Gboard Rambler is prompt-based, rather than real-time

Gboard Rambler is likely the flagship Gemini Intelligence feature on the Pixel 11 series, but it’s not the real-time transcription you expect. Read more @...

Google Meet rolling out ‘Take Notes’ for in-person meetings on Android, web, & iOS

As previewed in April, Google Meet’s “Take Notes for me” feature can now work for in-person meetings. Read more @ 9to5google