Google Youtube Android Player Api
By the Year
In 2023 there have been 1 vulnerability in Google Youtube Android Player Api with an average score of 7.3 out of ten. Youtube Android Player Api did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2023 as compared to last year.
It may take a day or so for new Youtube Android Player Api vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Google Youtube Android Player Api Security Vulnerabilities
The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App
7.3 - High
- March 01, 2023
The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from YouTube Main App by retrieving the Main Apps ClassLoader. A potential vulnerability in the binding logic used by the client SDK where the SDK ends up calling bindService() on a malicious app rather than YT Main App. This creates a vulnerability where the SDK can load the malicious apps ClassLoader instead, allowing the malicious app to load arbitrary code into the calling app whenever the embedded SDK is invoked. In order to trigger this vulnerability, an attacker must masquerade the Youtube app and install it on a device, have a second app that uses the Embedded player and typically distribute both to the victim outside of the Play Store.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Google Youtube Android Player Api or by Google? Click the Watch button to subscribe.