Dropbox for Android SDK Vulnerability Discovered by IBM | Internet News

Dropbox for Android SDK Vulnerability Discovered by IBM

Mar 12, 2015
1 minute read

The flaw, now identified as CVE-2014-8889, was found inside the Dropbox SDK (software development kit) for Android and could have potentially enabled an attacker to insert an arbitrary access token, to give the attacker access to user information.

IBM built a proof-of-concept exploit that it calls “DroppedIn” to test the impact of the vulnerability. Using the exploit, IBM found that 76 percent of the apps that it analyzed that leverage the Dropbox SDK were at risk from the flaw.

The vulnerability was just for the Dropbox SDK being used within Android apps; there is no indication that users of iOS or other operating systems would be affected. To be clear, it’s not Dropbox for Android itself that’s the big risk, but all of the apps on Android that leverage the Dropbox for Android SDK.

Read the full story at eSecurity Planet:
IBM Exposes Critical Dropbox Vulnerability

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.