Google and a cybersecurity firm are at odds over accusations that an app on Android phones has exposed devices to potential cyber threats and spyware.
On Thursday, the cybersecurity firm iVerify released a report detailing issues with an Android package known as “Showcase.apk,” which has been pre-installed on many Pixel devices worldwide since September 2017.
According to iVerify, Showcase.apk operates at the system level and is intended to convert phones into demo units, altering the operating system’s functionality. The firm claims this app makes millions of Android Pixel devices vulnerable to man-in-the-middle (MITM) attacks, allowing cybercriminals to inject malicious code and spyware.
iVerify’s researchers found the app on a device used by a Palantir employee. A Palantir executive confirmed that the company had flagged the device as insecure earlier this year, leading to an investigation that corroborated iVerify’s concerns about the app’s potential for hacker exploitation.
Palantir has decided to phase out Android devices over the coming years, not only due to this vulnerability but also past security issues.
Google, however, disagrees with many of iVerify’s assertions. In a statement to Recorded Future News, Google clarified that this issue does not represent a vulnerability within the Android platform or Pixel devices themselves. The package was developed by Smith Micro for Verizon to facilitate in-store demonstrations but is no longer in use.
According to Google, exploiting this app requires both physical access to the device and the user’s password, and there is no evidence of active exploitation. Nonetheless, Google plans to remove the app from all supported Pixel devices through an upcoming software update. It is not present on Pixel 9 series devices, and other Android manufacturers will be notified as well.
Verizon acknowledged the issue but noted that the demo capability is no longer used in stores or by consumers. They also stated that no evidence of exploitation has been found and supported the removal of the demo feature from all supported devices as a precaution.
iVerify’s co-founder, Rocky Cole, criticized Google’s stance, suggesting that the company made a business decision to deploy Verizon’s software across all Pixel devices without offering users an option to remove it. Cole argued that the necessity for physical access to exploit the package is speculative and insisted that the issue constitutes an Android vulnerability.
According to iVerify, the app’s system-level operation could potentially allow significant changes to the phone’s operating system. The firm had previously reported the issue to Google but did not receive confirmation on whether a patch or removal would be issued. iVerify contends that users cannot remove the app themselves, creating a dilemma for security leaders who must choose between accepting the risk of the app or abandoning Android devices entirely.
The researchers warned that, while there is no evidence of active exploitation, the vulnerability poses serious risks in corporate environments, where millions of Android phones are used daily. They also questioned why Google would need to install such an application on every Pixel device when only a few devices would require it.



