Hacker News with Generative AI: Mobile Security

Android Trojan that intercepts voice calls to banks just got more stealthy (arstechnica.com)
Researchers have found new versions of a sophisticated Android financial-fraud Trojan that’s notable for its ability to intercept calls a victim tries to place to customer-support personnel of their banks.
Man locked out of Google Drive and loses 9 year old photos after SIM Swap attack (bbc.co.uk)
A man says he has lost files, business records and all his online photos after "failings" by his mobile phone provider allowed fraudsters to take control of his phone.
Google Chrome will soon block password autofills if Android phone gets stolen (androidauthority.com)
Google Chrome for Android is preparing to add support for Identity Check, an upcoming feature that will force apps to use biometric authentication when your phone is outside of a trusted location.
Understanding the Android Virtualization Framework (AVF) (medium.com)
As the complexity of mobile applications and the sensitivity of the data they handle increase, so does the need for robust security solutions. Enter the Android Virtualization Framework (AVF), a groundbreaking innovation designed to enhance security, efficiency, and flexibility in Android devices.
Has my mobile security advice changed? (shkspr.mobi)
A decade ago, I appeared on the 361 Podcast to give my advice about mobile security.
Jailbreak Your Enemies with a Link: Remote Execution on iOS (jacobbartlett.substack.com)
This is the story of the Trident exploit chain: 3 zero-day vulnerabilities in iOS that enabled the first remote jailbreak. Part #1 dives into the internals of the JavaScriptCore runtime: where a vulnerability lurks in WebKit which would crack your iPhone wide open.
New Phishing Technique Bypasses Security on iOS and Android to Steal Bank Creds (securityweek.com)
Flaw has Microsoft Authenticator overwriting MFA accounts, locking users out (csoonline.com)
Hackers Steal Phone, SMS Records for Nearly All AT&T Customers (krebsonsecurity.com)
Europol says Home Routing mobile encryption feature aids criminals (bleepingcomputer.com)
Twilio breach leaks over 30M Authy-linked phone numbers (androidpolice.com)
3M iOS and macOS apps were exposed to potent supply-chain attacks (arstechnica.com)
British duo arrested for SMS phishing via homemade cell tower (theregister.com)
Apple has rejected UTM SE from the iOS and third party App Stores (twitter.com)
Attacking Android Binder (androidoffsec.withgoogle.com)
Hacking phones is too easy (economist.com)
Deleted iPhone photos show up again after iOS update (malwarebytes.com)
Bank scammers using genuine push notifications to trick their victims (shkspr.mobi)
Cracked Rabbit R1 APKs running on Android phone (twitter.com)
Over a billion users could be at risk from keyboard logging app security flaw (techradar.com)