The article discusses the discovery of malware in Pinduoduo's mobile app, which allows access to users' sensitive information without their consent. The malware was discovered by a Chinese cybersecurity firm called Dark Navy and later confirmed by other researchers.
**Key points:**
* The malware was found to be exploiting vulnerabilities in Android apps, allowing the app to request excessive permissions from users.
* Pinduoduo's app was specifically found to be requesting "set wallpaper" and "download without notification" permissions, which are considered invasive.
* The malware also allowed access to users' locations, contacts, calendars, notifications, and photo albums.
* The exploit code was removed after an update of the app, but tech experts warn that the underlying code could still be reactivated.
* Pinduoduo has been criticized for its lack of oversight and regulatory compliance.
**Regulatory context:**
* China's Ministry of Industry and Information Technology has regularly published lists of apps that have undermined user privacy or other rights.
* However, Pinduoduo did not appear on any of the lists.
* The Chinese government's data privacy legislation prohibits exploiting internet-related security vulnerabilities or engaging in actions that endanger cybersecurity.
**Consequences:**
* Users who installed the app may be at risk of their sensitive information being accessed without consent.
* The discovery highlights a lack of regulatory oversight and enforcement in China's tech industry.
* Pinduoduo has faced criticism for its handling of the issue, including the removal of the exploit code and the transfer of affected employees to other departments.
**Key points:**
* The malware was found to be exploiting vulnerabilities in Android apps, allowing the app to request excessive permissions from users.
* Pinduoduo's app was specifically found to be requesting "set wallpaper" and "download without notification" permissions, which are considered invasive.
* The malware also allowed access to users' locations, contacts, calendars, notifications, and photo albums.
* The exploit code was removed after an update of the app, but tech experts warn that the underlying code could still be reactivated.
* Pinduoduo has been criticized for its lack of oversight and regulatory compliance.
**Regulatory context:**
* China's Ministry of Industry and Information Technology has regularly published lists of apps that have undermined user privacy or other rights.
* However, Pinduoduo did not appear on any of the lists.
* The Chinese government's data privacy legislation prohibits exploiting internet-related security vulnerabilities or engaging in actions that endanger cybersecurity.
**Consequences:**
* Users who installed the app may be at risk of their sensitive information being accessed without consent.
* The discovery highlights a lack of regulatory oversight and enforcement in China's tech industry.
* Pinduoduo has faced criticism for its handling of the issue, including the removal of the exploit code and the transfer of affected employees to other departments.