Google to Remove Vulnerable App from Pixel Devices in Upcoming Update

16 Aug 2024

Security Concerns Surrounding Google’s Pixel Devices

A significant discovery has emerged regarding a portion of Google’s Pixel devices, which have been in circulation since September 2017. Research conducted by the mobile security firm iVerify reveals that these devices contain a dormant software component capable of facilitating malicious attacks and deploying various forms of malware.

The focal point of this issue is an Android application known as “Showcase.apk.” This app possesses extensive system privileges, allowing it to execute code remotely and install arbitrary packages on the device. According to the analysis, which was conducted in collaboration with Palantir Technologies and Trail of Bits, the application retrieves a configuration file through an unsecured connection, raising serious security concerns.

Specifically, the app downloads its configuration from a single U.S.-based, AWS-hosted domain via unsecured HTTP. This vulnerability not only exposes the configuration file but also leaves the device open to potential exploitation.

Further investigation identifies the app as Verizon Retail Demo Mode (“com.customermobile.preload.vzw”), which has been noted to require nearly three dozen permissions, including access to location and external storage. Interestingly, discussions on platforms like Reddit and XDA Forums indicate that this package has been in existence since August 2016.

The core of the security dilemma lies in the app’s reliance on an unencrypted HTTP connection for downloading its configuration file, rather than utilizing the more secure HTTPS protocol. This oversight creates an opportunity for malicious actors to manipulate the file during its transit to the targeted device. Fortunately, there is currently no evidence suggesting that this vulnerability has been exploited in the wild.

It is important to clarify that Showcase.apk is not a product of Google; rather, it is developed by Smith Micro, an enterprise software company, specifically for demo purposes. The rationale behind embedding third-party software directly into Android firmware remains unclear. However, a representative from Google stated that the application is mandated by Verizon for all Android devices.

This situation ultimately renders Android Pixel smartphones vulnerable to adversary-in-the-middle (AitM) attacks, which could allow malicious entities to inject harmful code and spyware. The application operates with elevated privileges at the system level, yet it fails to authenticate or verify the domain from which it retrieves its configuration file. Additionally, it employs insecure default variable initialization during certificate and signature verification, leading to potential validation checks succeeding despite failures.

Despite the severity of these shortcomings, the risk is somewhat mitigated by the fact that the app is not activated by default. However, should a threat actor gain physical access to a device with developer mode enabled, they could potentially exploit this vulnerability.

iVerify has pointed out that since the app is not inherently malicious, traditional security technologies may overlook it, failing to flag it as a threat. Furthermore, being installed at the system level as part of the firmware image means that users cannot uninstall it.

In a statement to The Hacker News, Google clarified that this issue does not represent a vulnerability within the Android platform or Pixel devices themselves, but rather pertains to a package developed for Verizon’s in-store demo devices. The company also noted that the app is no longer in use.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6655228
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1390129
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
550824
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
460399
downloads

News and reviews for Mobile Android

CISA Warns of Increasing Messaging App Threats

CISA alerts users to heightened threats against messaging apps like WhatsApp, Telegram, and Signal.

Read more

Android Deals Highlight Major Game Discounts for 2025

9to5Toys reveals Android deals with significant discounts on apps like Rush Rally Origins. Savings for tech enthusiasts.

Read more

Libby Adds AI and Expands Device Compatibility

Libby now includes AI book suggestions and runs on Android e-readers like Onyx Boox and Bigme. Update enhances user experience.

Read more

X Launches Hidden Android Redesign, Offers Subscription Discounts

X unveils a secret Android redesign in version 11.42.0-release.0 and offers discount subscriptions. Available until 2025-12-02 in India and beyond.

Read more

Cryptomining Apps in 2025 Transform Passive Earning

Cryptomining apps in 2025 leverage mobile, cloud tech for ease; key into short-cycle contracts and renewable sources.

Read more

Top Offline Mobile Games to Try in November 2025

Explore the latest offline games for Android and iOS this November. Enjoy roguelike adventures, puzzles, and more without an internet connection.

Read more

Journey Offers Comprehensive Cross-Platform Journaling

Journey app available cross-platform, matches Google's Pixel-only Journal. Flexible design enhances journaling experience.

Read more

Launch Remix Feature in Google Messages

Google Messages adds Remix feature for image generation using Nano Banana model in app, starting 2025-11-26.

Read more

Google Enhances Gemini with 'Projects' Feature

Google's Gemini app is set to gain a 'Projects' feature, enhancing user-focused AI research and organization capabilities.

Read more

Norton Introduces Black Friday Discounts on Security Plans

Norton has launched Black Friday discounts on antivirus and security plans across regions, benefiting individual and business users.

Read more