<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o" -->

---
title: Google Pixel Devices Shipped with Vulnerable App Since...
description: A security vulnerability was discovered in the pre-installed &#x27;Showcase.apk&#x27; app on Google Pixel devices, posing risks of adversary-in-the-middle attacks and...
canonical: https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Google Pixel Devices Shipped with Vulnerable App Since 2017, Update to Remove It | daily.dev
og:description: A security vulnerability was discovered in the pre-installed &#x27;Showcase.apk&#x27; app on Google Pixel devices, posing risks of adversary-in-the-middle attacks and...
og:url: https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o
og:image: https://api.daily.dev/og/posts/BiLygXL9O.png
og:image:alt: Google Pixel Devices Shipped with Vulnerable App Since 2017, Update to Remove It
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Pixel Devices Shipped with Vulnerable App Since 2017, Update to Remove It

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A security vulnerability was discovered in the pre-installed 'Showcase.apk' app on Google Pixel devices, posing risks of adversary-in-the-middle attacks and potential spyware functionality. Developed by Smith Micro Software for in-store demos, the app could download configuration files over unencrypted HTTP connections. Google has committed to removing the app from all supported Pixel devices as a precaution to enhance user security.

## Content

# Security Vulnerability Discovered in Pre-installed App on Google Pixel Devices

Since September 2017, numerous Google Pixel devices have been shipped with a pre-installed app known as 'Showcase.apk', developed by Smith Micro Software at Verizon's request for in-store demo purposes. Despite its intended function, the app has posed significant security risks.

## The Security Concerns

The 'Showcase.apk' app was found to be capable of downloading configuration files over unencrypted HTTP connections. This vulnerability opens the door to potential adversary-in-the-middle attacks, where malicious actors could intercept and manipulate these unencrypted communications. Although Google asserts that the app is not inherently malicious by design, it acknowledges the security risks if an attacker gains physical access to the device and knows the user's password.

Additionally, the app contained inactive remote maintenance software that, if activated under specific conditions requiring physical access and user credentials, could potentially transform the device into a tool for spyware. These revelations have raised significant concerns regarding transparency and the inclusion of third-party apps in the system firmware.

## Response and Mitigation

Upon discovery of these vulnerabilities by cybersecurity firm iVerify, Google has committed to removing 'Showcase.apk' from all supported Pixel devices. Both Google and Verizon have emphasized that there is no known evidence of active exploitation. However, the update to remove the app will serve as a precautionary measure to enhance device security and protect users from potential threats.

## Conclusion

This incident underscores the importance of rigorous security assessments for pre-installed software on consumer devices. While the app in question was originally meant for a benign purpose, its vulnerabilities highlight the need for ongoing vigilance in maintaining device security and user privacy.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#android](https://daily.dev/tags/android)

[View this post on daily.dev](https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Google Pixel Devices Shipped with Vulnerable App Since 2017, Update to Remove It","url":"https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o"},"datePublished":"2024-08-16T07:17:05.542Z","dateModified":"2024-08-16T10:58:16.933Z","description":"A security vulnerability was discovered in the pre-installed 'Showcase.apk' app on Google Pixel devices, posing risks of adversary-in-the-middle attacks and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/69034bd998e4a2d60f6c5c7fb3c49efc?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/69034bd998e4a2d60f6c5c7fb3c49efc?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/google-pixel-devices-shipped-with-vulnerable-app-since-2017-update-to-remove-it-bilygxl9o","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,android","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Google Pixel Devices Shipped with Vulnerable App Since 2017, Update to Remove It"}]}
```

