{"id":80889,"date":"2015-11-17T14:22:26","date_gmt":"2015-11-17T08:52:26","guid":{"rendered":"https:\/\/blogs.quickheal.com\/?p=80889"},"modified":"2016-04-14T11:50:05","modified_gmt":"2016-04-14T06:20:05","slug":"security-hole-in-gmail-android-app-makes-phishing-attacks-easier","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/security-hole-in-gmail-android-app-makes-phishing-attacks-easier\/","title":{"rendered":"Security Hole in Gmail Android App Makes Phishing Attacks Easier"},"content":{"rendered":"<p>A recently discovered bug in the\u00a0Gmail Android App allows anyone to pose as someone else, hiding their real email address. Although labelled as a \u201cnon-issue\u201d by Google Security Team, the flaw can prove to be helpful for online scammers. Read the rest of the story from the post that follows.<\/p>\n<p>Phishing has been one of the oldest tricks in the history of cyberattacks. And with time, scammers have been able to devise new and slier ways to trick people into phishing traps. And a new security bug discovery by Yan Zhu, an independent security researcher, may just make this trick more successful.<\/p>\n<p>This security bug is known to affect the Gmail Android app as of now. <strong>This is how it works<\/strong>:<br \/>\nIf the user changes their display name in the Gmail Account Settings, their real email address will be hidden in the recipient\u2019s inbox.<\/p>\n<p>For instance, if you change your display name to <strong>\u201c\u201dsecurity@google.com\u201d<\/strong>, the same name will be displayed in every email that you send out. And in that email, your real email address will be hidden; and there\u2019s no way to reveal it.<\/p>\n<p><strong>So, how does this bug encourage phishing attacks?<\/strong><br \/>\nThis flaw is more likely to be abused by online scammers who could spoof their display name to some trusted or reputed entity such as a popular online shopping site, a bank, a financial organization or companies like Google, Facebook, etc. To unsuspecting users, a sender with the name <strong>security@facebook.com<\/strong> or <strong>security@google.com<\/strong> may not appear suspicious. And this is where, they could fall into a phishing trap.<\/p>\n<p><a href=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2015\/11\/Gmail-Android-App-Display-Name-Flaw.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-80891\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2015\/11\/Gmail-Android-App-Display-Name-Flaw.jpg\" alt=\"Gmail Android App Display Name Flaw\" width=\"254\" height=\"451\" \/><\/a><br \/>\nHowever, it is important to note that, this security flaw only gets triggered if the display name has extra quotation marks in it &#8211; for instance, <strong>\u201c\u201dsecurity@google.com\u201d<\/strong><\/p>\n<p>On the other hand, if the display name does not have these quotation marks, the bug won\u2019t get triggered, and the recipient will be able to view the real email address of the sender.<\/p>\n<p><strong>So, the bottom line remains the same<\/strong><br \/>\nBeware of any kind of unexpected or unwanted email, regardless of who is sending it to you. If the email sounds urgent or important, you can always give a call to the sender and have the information verified. Also, having a <a href=\"https:\/\/www.quickheal.co.in\/home-users\/quick-heal-total-security-for-android\" target=\"_blank\">mobile antivirus<\/a> app that can block spam, phishing, and malicious emails, adds to your security.<\/p>\n<p>If you think this post is helpful, <a href=\"https:\/\/www.facebook.com\/sharer\/sharer.php?app_id=188707654478&amp;sdk=joey&amp;u=http%3A%2F%2Fblogs.quickheal.com%2Fwp%2Fsecurity-hole-in-android-gmail-app-makes-phishing-attacks-easier%2F&amp;display=popup&amp;ref=plugin&amp;src=share_button\" target=\"_blank\">share <\/a>it with your friends, family members, and acquaintances. If you wish to receive such alerts and security tips directly to your inbox, then click here to <a href=\"https:\/\/feedburner.google.com\/fb\/a\/mailverify?uri=quickhealav\" target=\"_blank\">subscribe <\/a>to our blog. Stay safe!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recently discovered bug in the\u00a0Gmail Android App allows anyone to pose as someone else, hiding their real email address. Although labelled as a \u201cnon-issue\u201d by Google Security Team, the flaw can prove to be helpful for online scammers. Read the rest of the story from the post that follows. Phishing has been one of [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":82579,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,303,60,6],"tags":[431,407,534,604,99,1252,1175,19,25,1253,1254],"class_list":["post-80889","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","category-phishing","category-smartphone","category-tips","tag-android","tag-bug","tag-cybersecurity","tag-flaw","tag-gmail","tag-information-security","tag-internet-insecurity","tag-news","tag-phishing","tag-security-bug","tag-tech-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/80889"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=80889"}],"version-history":[{"count":4,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/80889\/revisions"}],"predecessor-version":[{"id":82580,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/80889\/revisions\/82580"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/82579"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=80889"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=80889"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=80889"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}