    New Malicious Apps Can Gain System Privilege As Rom Is Signed With Default Platform Key

    It seems all ROMs are signed with the default Android platform private key. This is a severe security flaw. Any arbitrary userland apps (installed by users using apk files) can gain System privilege by claiming android:sharedUserId="android.uid.system" in the manifest xml file. Here...