Android Camera Flaw Discovered That Lets Attackers Record Videos, Take Photos, GPS Data Without Permission: Checkmarx

Google and Samsung have fixed the camera apps on their Android devices, but some other smartphone makers might haven't yet patched their offerings.

Advertisement
By Jagmeet Singh | Updated: 20 November 2019 15:37 IST
Highlights
  • Checkmarx researchers notified Google about the flaw
  • Google raised the severity of the finding to "High" on July 23
  • Samsung on August 29 confirmed that its camera app also affected

Attackers could utilise the flaw to control the camera of your Android smartphone

An Android camera flaw has been reported that could allow attackers to take pictures, record videos, or extract GPS data without requiring any explicit permissions from users. The loophole, which was spotted on the Google Camera app available on Pixel devices and the Samsung Camera app that comes preloaded on Galaxy devices, can be executed remotely using a malicious app. It is known to be available on the Google Camera and Samsung Camera apps until July 2019 and is listed as CVE-2019-2234.

The vulnerability has been discovered by a team of security researchers at Checkmarx. The researchers found that while an app generally requires to obtain certain permissions to record videos, take pictures, and access GPS metadata, apps that have the default 'Storage' permission to use the device's SD card and its media content can exploit the Camera app to gain access to capture photos, videos, or obtain EXIF data and geolocation details. The flaw was noticed after analysing the Google camera app. However, it is also said to have existed in the Samsung Camera app.

"[O]ur researchers determined a way to enable a rogue application to force the camera apps to take photos and record video, even if the phone is locked or the screen is turned off. Our researchers could do the same even when a user was is in the middle of a voice call," Checkmarx researchers noted in a blog post.

Advertisement

There are a large number of apps on Google Play that ask for the Storage permission. Thus, the scope of the Android camera flaw appears to be quite wide.

Advertisement

Checkmarx researchers created a proof-of-concept app that works as a weather app but silently transmits a picture, video, and phone call recordings to a command-and-control server. The team after confirming the issue through the proof-of-concept app notified Google of its findings on July 4. The search giant had raised the severity of the finding to "High" on July 23 and noted that it may affect other Android smartphone vendors. Google also issued CVE-2019-2234 to help smartphone vendors fix the flaw on their Android devices.

"We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure. The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners," Google said in a statement.

Advertisement

Checkmarx researchers said Samsung on August 29 also confirmed that the flaw had affected their camera app. The South Korean company -- just like Google - however, has fixed the issue.

That being said, it is still unclear whether other Android vendors have followed in the footsteps of Google and Samsung and fixed the vulnerability on their devices. It is recommended to have the latest software updates along with the most recent app versions to avoid uncertainties.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing CEO Carl Pei Announces March 5 Event
  2. Realme P4 Power Review
  3. Lava Bold N2 Launched in India With a 5,000mAh Battery at This Price
  4. Xiaomi 17 Ultra Leica Edition Lands on Geekbench With This Snapdragon Chip
  5. Apple Reportedly Announces 'Special Experience' on March 4
  6. AI Impact Summit: Here's a Look at Sarvam's First AI Smart Glasses
  7. Samsung Galaxy S26 Ultra Could Launch With This Selfie Camera Upgrade
  8. Vivo V60 Lite 4G (2026) Debuts With Updated Snapdragon Chipset
  9. Vivo V70 FE Promo Image Tip Design; RAM, Storage Options Leaked
  10. Samsung Galaxy Buds 4Series Renders Leak Ahead of Galaxy Unpacked Event
  1. Vivo X300 FE Tipped to Launch in Two RAM and Storage Configurations: Expected Features, Colourways and More
  2. AI Impact Summit: Sarvam Kaze Smart Glasses Showcased, Will Launch in India in May
  3. Vivo V70 FE Design Seen in Leaked Promo Image; Tipster Leaks RAM and Storage Configurations
  4. Sony Reportedly Develops New Tech That Can Trace Original Music in AI Songs
  5. Assassin's Creed Shadows Gets Manual Jump Feature With Title Update 1.1.8
  6. Eternity Now Available for Streaming on Apple TV+: Where to Watch Elizabeth Olsen and Miles Teller’s Afterlife Rom-Com?
  7. Xiaomi 17 Ultra Leica Edition Visits Geekbench Ahead of Global Launch: Expected Specifications, Features
  8. Samsung Galaxy F70e 5G With 120Hz LCD Screen, Dimensity 6300 SoC Goes on Sale in India: Price, Offers
  9. Hackers Send Physical Phishing Letters Impersonating Trezor and Ledger to Trick Users
  10. Paathirathri OTT Release Date: When and Where to Watch Navya Nair and Soubin Shahir Starrer Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.