The security firm Promon uncovered the Android vulnerability called StrandHogg. The report states that it has infected all the Android versions and also has affected 500 popular apps. StrandHogg copy any app on the infected device and users get tricked by believing it to be the legitimate app. The vulnerability then allows malicious apps to phish users' credentials by displaying a malicious and fake version of a login screen.