Heartbleed Scanners Found to be Lacking | Internet News

Heartbleed Scanners Found to be Lacking

Apr 24, 2014
1 minute read

To add further insult to injury for end users, FireEye found that apps that claim to scan for the Heartbleed flaw on Android, for the most part, don’t really work. Looking at 17 different apps that claim to scan for Heartbleed, FireEye found that 11 of them did not scan apps for the Heartbleed flaw.

Going a level deeper, looking at the six that did scan for Heartbleed, two of them did not correctly identify apps that were in fact vulnerable to Heartbleed.

“Only two of them did a decent check on Heartbleed vulnerability of apps,” FireEye researchers noted in a blog post. “We’ve also seen several fake Heartbleed detectors in the 17 apps, which don’t perform real detections nor display detection results to users and only serve as adware.”

While the risk to Android apps is nontrivial and should be taken seriously, attacks against Android apps are not happening—yet.

“We haven’t observed active exploits yet, but given the scale, it’s important for Android users to be aware of the ongoing threat,” Xue said.

Read the full story at eWEEK:
Heartbleed Puts 150 Million Android App Downloads at Risk

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.