this post was submitted on 01 Dec 2025
148 points (99.3% liked)

Android

20787 readers
156 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: !android@lemdro.id


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 2 years ago
MODERATORS
top 20 comments
sorted by: hot top controversial new old
[–] OR3X@lemmy.world 38 points 1 week ago (1 children)

Once again being lazy and not updating my shit has averted potential disaster.

[–] limerod@reddthat.com 1 points 1 week ago (1 children)

This is a 3rd party youtube client. Did it not stop working when you did not update the app for almost a whole month?

[–] OR3X@lemmy.world 28 points 1 week ago (1 children)

Nope. In fact, I only ever bother to update it when I have issues with playback which is maybe one every few months.

[–] moonburster@lemmy.world 1 points 6 days ago

Vanced I do the same. When it stops working months have passed

[–] limerod@reddthat.com 24 points 1 week ago (1 children)

Fortunately, its an app for TVs. Still, sometimes you have to be extra careful when downloading 3rd party apps. Especially, those which do not exist on fdroid.

[–] Stitch0815@feddit.org 9 points 1 week ago (1 children)

It would not matter in this case, or? The official SDK was compromised since his building machine was compromised?

[–] limerod@reddthat.com 5 points 1 week ago (1 children)

The app is limited for TV which limits the reach. Plus, I do not download apps outside of fdroid for the most part.

[–] Scipitie@lemmy.dbzer0.com 9 points 1 week ago

It's the Google account people log onto with thats the issue from a security perspective.

That said neither a malicious update was so far identified nor anything that 2FA wouldn't take care of.

This can happen to fdroid apps as well by the way. It's just the downside of small or solo devs that they are on their own when it happens.

I'm actually more confident in the smarttube rev now I have to say. He disclosed it fast, flagged his own apps as compromised even without specific proof and published it from what I can tell pretty much right after finding out.

[–] artyom@piefed.social 19 points 1 week ago* (last edited 1 week ago) (1 children)

If you use SmartTube and are concerned about your exposure to this malware, you should factory reset any device that had the app installed

Fuuuuugg

I don't have a Google account. I'm just going to delete and redownload 😮‍💨

[–] otter@lemmy.ca 14 points 1 week ago

From the comments of the article

Deleting it and re-installing from the new uncompromised release is not a big deal, but having to go and factory reset all one’s streaming devices and re-configure them from scratch is rather time consuming (I have several).

In yuliskov’s github announcement, he doesn’t come across as this being particularly urgent, and is NOT making statements like “reset all your devices, change all your streaming account passwords”. He just said going forward there won’t be updates and it will have to be re-installed from the new tree.

It seems at this point for most people, if google and amazon haven’t uninstalled it and you are not running 30.43 or 30.47, then keep using it, and when the new version is released, remove the old one and install the new one.

Factory resetting is likely overkill. Android apps are, theoretically, sandboxed, so they shouldn’t be able to affect the system or other apps. Uninstalling the infected app should be enough to clean up, but a factory reset is a guaranteed way, which is why I mention it.

[–] JakenVeina@midwest.social 8 points 1 week ago (1 children)

Shite, I'm pretty damned sure I updated like a week ago. The updates always pop up in the main menu of the app, and they often mean a fix for google's latest anti-adblock measures, so I usually update right away. I should probably adjust that policy to add some delay.

[–] bl4kers@beehaw.org 1 points 1 week ago* (last edited 1 week ago)

Pretty sure if you downloaded/updated from within the app you should be fine, as the threat is for net new installs

[–] LiveLM@lemmy.zip 8 points 1 week ago* (last edited 1 week ago)

Ugh, and lately I was having some playback woes so I was updating the app as soon as a new update was available 😵‍💫

Just revoked its access to my Google Account, now to remove it, install and setup the clean version on my TV Box 😮‍💨

Thanks for posting this!

[–] 01189998819991197253@infosec.pub 5 points 1 week ago (1 children)

Are we all ready for the inevitable "FLOSS is bad, and here is why" flood of bullshit?

[–] possiblylinux127@lemmy.zip 0 points 1 week ago

It has nothing to do with FOSS (although it being FOSS helps a lot)

[–] Stitch0815@feddit.org 5 points 1 week ago

Ahhh I was wondering why it hat disappeared.

I thought it was just google with their usual anti addblock shenanigans.

So if I was still on version 1.29 I don't need to worry? I've unit for now just to make sure I can't update to an infected version

[–] quick_snail@feddit.nl 1 points 1 week ago (1 children)

This is why I don't install software that's not on fdroid