Google claims that its Pixel smartphones offer enhanced security, as they are equipped with a clean version of Android supposedly free of additional overlays and third-party software. However, cybersecurity experts from iVerify have discovered that all phones in this series, starting from September 2017, come with a hidden third-party application that makes them vulnerable to hacking.
The application in question is called Showcase.apk, which operates at the system level and remains invisible to users. It was developed by Smith Micro for the American carrier Verizon — the app is intended to switch phones into demo mode in retail stores and is not affiliated with Google.
Yet, for nearly seven years, it has been included in every Android release for Pixel devices and has deep system privileges, including remote code execution and the ability to install other software. Additionally, the app allows configuration files to be loaded via an unsecured HTTP connection, which could be intercepted by potential attackers to gain control over the app and, subsequently, the entire device.
iVerify reported its findings to Google in early May, but the tech giant has yet to address the issue. Google spokesperson Ed Fernandez assured Wired that the app, which is no longer used by Verizon, will be removed from all supported Pixel devices with an upcoming Android update “in the next few weeks.” Verizon confirmed that Showcase was previously used for retail demonstrations but is no longer in use. Smith Micro did not provide any comments.
Although Showcase.apk represents a significant security vulnerability for phones, the app is disabled by default. This means that a potential cybercriminal would need physical access to the victim’s phone to activate the app for malicious purposes. iVerify also suggested that Showcase.apk might be installed on devices from other manufacturers as well. Ed Fernandez indirectly confirmed this, stating that “we are also notifying other Android OEMs.”
month
week
day