Toastamigo is the first weaponisation of the concept and it affects all versions of Android except for Android Oreo and devices which have received the September 2017 or later security patch. Asking users to grant accessibility service access, the applications in question then used the exploit to draw an “analysing apps” overlay over the screen as it began to grant itself administrator access and install another application on the device dubbed Clickamigo, by formulating tap actions using the accessibility service granted.
Read full news article on E Hacking News