PrivSec-dev / banking-apps-compat-report

Report and track banking app compatibility with GrapheneOS, including which workarounds may be required.
https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/
87 stars 4 forks source link

Nordea Mobile - Norge #452

Closed tegan-lamoureux closed 5 months ago

tegan-lamoureux commented 5 months ago

Is there an existing issue for this?

App name

Nordea Mobile - Norge

Link to app

https://play.google.com/store/apps/details?id=no.nordea.mobilebank

App version

4.16.1.1002820

Country of the app

Norway

Build Number

2024052100

Device list

Pixel 8

Profile app tested in

Owner profile, Secondary profile(s)

Google Play installed?

Installed

Where did you install this app from?

Google Play Store

Google Play services Network permission revoked?

Native code debugging

Exploit protection compatibility mode

Memory tagging extension (MTE)

Stock OS compatibility

NFC payments

Description of the app's functionality

App starts, allows me to log in with BankID (our national ID system in Norway), and then finds a problem with the accessibility services and refuses to open further (see below screenshots). This is the only and final screen, can do nothing else.

I do not have any accessibility apps installed / enabled. This happened after the app updated today, worked fine before. Also tried in a secondary user profile with just this app and all settings opened as described above. Same behaviour.

Uninstalled and reinstalled. Same behaviour.

Screenshot (changed system language settings to English to get the translation; Normally system and app is in Norwegian): 1000000557 1000000564 1000000565

Are there any extra notes you think users should know about?

App logs (field below doesn't allow attachments)

Nordea Mobile log ea4a732ed2f1.txt

ADB logcat of the app if necessary

Logs attached above.
tegan-lamoureux commented 5 months ago

Seems it's most of the Nordics affected, so same for Sweden, Denmark, and Finland.

https://discuss.grapheneos.org/d/13006-nordea-mobile-danish-claims-malicious-software-running

tegan-lamoureux commented 5 months ago

Okay, root cause found by lbschenkel on the Graphene forum. We need to disable the system Talk Back accessibility app. (Disable the app entirely, not just the service in Accessibility Settings.) Seems to allow the app to start.

https://discuss.grapheneos.org/d/13006-nordea-mobile-danish-claims-malicious-software-running/30

spring-onion commented 5 months ago

Luckily that's no longer necessary. Thanks for the report!

tegan-lamoureux commented 5 months ago

No problem! Nice that the right people listened.

Seems the fix was server-side so I'll close, shouldn't be too many people needing to do anything now. :)