












Screen readers may be the latest malware to watch out for, according to testing from app shielding expert Promon. The company uncovered some pretty disturbing vulnerabilities among the top financial apps on the Google Play Store. Let’s take a look.
Screen readers are used to transform digital text into synthesised speech or braille output. That makes them essential tools for accessibility. And unsurprisingly, their main purpose is to aid visually impaired individuals in navigating and engaging with digital content.
However, the extensive access required by screen readers and other accessibility services poses a potential risk for misuse, as it grants wide-ranging access to the screen and its contents.
- Advertisement -
The gap between a 65% and 90%+ privacy opt-in rate can mean $525,000 in lost revenue annually for a 100K DAU app — and most teams have no idea where they stand.
This guide breaks down the true cost of consent debt, why the average app sits at just 80% opt-in, and the exact tactics top performers use to consistently hit 90%+: prompt timing, banner design, vendor list optimization, and more.
Malware that can access a user’s screen is also capable of stealing sensitive information, intercepting two-factor authentication, controlling the device and bypassing security features.
The Security Research team at Promon developed a simulated malicious screen reader capable of reading and extracting data from an application. They conducted tests on 100 apps and found that the screen reader program successfully read and exfiltrated data from 85 out of 92 apps (92.4%). Only seven apps (7.6%) demonstrated effective defence mechanisms against the screen reader’s attempts to access the data.
Android’s operating system contains numerous loopholes that malicious actors frequently exploit to infiltrate devices and acquire unauthorised access to sensitive information. This information encompasses confidential conversations, personal data, and financial transactions.
Through the exploitation of these vulnerabilities, malware can operate silently in the background, executing tasks and actions without the user’s knowledge. This includes the covert reading and interception of content displayed on users’ screens, even within financial apps responsible for handling delicate data like banking transactions, PINs, and account balances.
Majority of financial services apps not adequately protected against screen reader malware

Source: Promon
Malware with elevated permissions can also exfiltrate captured data through various channels, allowing analysis, extraction of personal details, and exploitation for financial gain or illegal activities.
App Shielding technology can help mitigate the threat of malicious screen readers, but developers can also take immediate steps. They can implement code to detect screen readers and decide whether to display a warning, shut down the app, or continue normally. However, these solutions have drawbacks, such as warning messages being bypassed by malware. Developers can verify the application using accessibility features to avoid shutting down legitimate apps.
Furthermore, upcoming security features in Android 14 aim to prevent accessibility service abuse. Developers will be able to restrict non-accessibility tools from interacting with their app, ensuring that only declared tools can access certain views.
Although this is a positive development, it’s important to note that the rollout of Android 14 will take time, and OS features should always be complemented with strong defensive measures at the app level to safeguard end-users.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。