Google says it will remove Showcase.apk from Pixel devices “out of an abundance of precaution”, after iVerify said hackers could use the dormant app to spy
Discovery prompted one intelligence contractor to stop issuing Android phones to employees.
The immediate significance is not only the dormant app’s alleged risk but the response from a security-sensitive employer: an intelligence contractor reportedly stopped issuing Android phones after the discovery. That raises the stakes for Pixel’s enterprise and institutional trust.
First-order effects
Google will remove Showcase.apk from Pixel devices, eliminating the dormant component identified by iVerify as a potential route for spying.
Pixel users and organizations issuing Android phones must reassess whether affected devices remain acceptable under their security policies; the reported contractor pause shows that review is already affecting procurement.
Second-order effects
Google faces pressure to show that preinstalled or dormant components receive the same scrutiny as apps distributed through Play, particularly for customers with high-security requirements.
Mobile-device buyers may place greater weight on vendor remediation speed and software-component transparency when choosing Android devices or setting fleet policies.
Third-order effects
If security buyers increasingly treat dormant, preloaded software as part of device supply-chain risk, handset makers will face stronger incentives to minimize and document nonessential system components.
The episode reinforces a shift from app-store-centric security controls toward lifecycle assurance for the full device image, from factory software through patches and removals.
The trend: Mobile security is moving toward tighter scrutiny of every software component shipped on a device, not just the apps users install.
@IsMyPhoneHacked I did some digging and the Showcase.apk app is actually called Retail Demo Mode. Pname com.customermobile.preload.vzw It is indeed present/installed on my unlocked Pixel 8 Pro. https://www.apkmirror.com/...
There is a new vulnerability report which states that all Pixel devices before the P9 are susceptible to being hacked through a system app called Showcase. The app was created by shitty Smith Micro developers for Verizon, but ships on every Pixel device. https://www.wired.com/...
The vulnerability stems from flawed logic in the verify() method. It checks both ‘payload’ and ‘payload_gzip’ fields, but only one needs to pass verification. An attacker can exploit this by injecting a malicious ‘payload’ while keeping a valid ‘payload_gzip’.
We identified several on-disk artifacts to help organizations detect if this app is on their devices, including specific files in the app's directory and SQLite databases. It may also modify certain system files.
iVerify Discovers Severe Android Vulnerability Impacting Millions of Devices Around the World. The vulnerability leaves millions of devices susceptible to man-in-the-middle (MITM) attacks and other dangerous malware and spyware. https://iverify.io/... [image]
Showcase.apk is disabled by default but can be manually enabled. Once active, it downloads a config file over HTTP. @trailofbits discovered the app's signature verification for this config is broken, and malicious configs can be provided.
.@IsMyPhoneHacked uncovered a hidden Android app “Showcase.apk” pre-installed on Google Pixel phones since 2017. This old Verizon demo app can potentially lead to remote code execution on millions of Android phones. https://x.com/...
With our partners at @IsMyPhoneHacked, we discovered an extremely privileged and insecure third-party app baked into Android firmware. Can't be removed, extensive permissions, insecure C2, no explanation for why it was there. https://www.wired.com/... https://www.washingtonpost.c…