900 Million Android Devices Affected by Critical 'QuadRooter' Vulnerability: Report

Advertisement
By Ketan Pratap | Updated: 12 August 2016 17:00 IST
Highlights
  • If exploited QuadRooter flaw gives attackers complete control of devices
  • QuadRooter flaw found in software drivers that ship with Qualcomm SoCs
  • Qualcomm claims that patches were released for the flaw

A new Android flaw has been reported by security researchers that is claimed to affect roughly 900 million Android devices. Check Point mobile research team first reported the issue and claims that it affects all devices using Qualcomm chipsets.

Dubbed 'QuadRooter', it is said to be a set of four vulnerabilities affecting Android devices built on Qualcomm chipsets. The research team explains that if any one of the four vulnerabilities is exploited, an attacker can trigger privilege escalations for the purpose of gaining root access to a device. The team also claimed that the QuadRooter vulnerabilities are present in software drivers that ship with Qualcomm SoCs. "Any Android device built using these chipsets is at risk," notes Check Point.

Qualcomm informed ZDNet that patches for the issue were released to "customers, partners, and the open source community between April and the end of July." Three patches so far have been made available via Google's monthly Android security update, while the fourth will be issued in September.

Advertisement

One of the biggest concerns with the QuadRooter vulnerability is that the buggy software is pre-installed on devices at the point of manufacture, and can only be fixed via security patch released by the carrier or distributor. "Distributors and carriers issuing patches can only do so after receiving fixed driver packs from Qualcomm," adds Check Point in a blog post.

Advertisement

"An attacker can exploit these vulnerabilities using a malicious app. Such an app would require no special permissions to take advantage of these vulnerabilities, alleviating any suspicion users may have when installing," explains Check Point mobile research team.

Some of the popular devices said to be affected by the new QuadRooter flaw include BlackBerry Priv, Google Nexus 5X, Nexus 6P, HTC 10, LG G5, Moto X, OnePlus 3, and Samsung Galaxy S7 among others. The team also claimed that secure phones - Blackphone 1 and Blackphone 2 - are also likely to be affected by this vulnerability. Adam Donenfeld, Lead Mobile Security Researcher at Check Point, revealed the vulnerability at a recent Def Con security conference in Las Vegas.

Advertisement

"If exploited, QuadRooter vulnerabilities can give attackers complete control of devices and unrestricted access to sensitive personal and enterprise data on them. Access could also provide an attacker with capabilities such as keylogging, GPS tracking, and recording video and audio," adds the team.

A Qualcomm spokesperson told ZDNet, "Qualcomm has a significant position in the development chain, in that a phone maker isn't taking the Android open-source code directly from Google, they're actually taking it from Qualcomm. No-one at this point has a device that's fully secure. That basically relates to the fact that there is some kind of issue of who fixes what between Qualcomm and Google."

Advertisement

Check Point recommends some best practices to keep Android devices safe from such attacks like downloading and installing the latest Android update; examine any app installation request before accepting; avoid side-loading Android apps, and read permission requests when installing any apps among others.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series India Launch Date, Price Range Leaked
  2. Shine On Me Now Streaming Online: Know Everything About Plot, Cast, and More
  3. Honor Win Series Camera Specifications Tipped Days Ahead of China Launch
  4. Motorola Edge 70 Goes on Sale in India: See Price, Offers, Features
  5. Xiaomi 17 Ultra, Poco X8 Pro Spotted on IMDA Ahead of Global Launch
  6. Clair Obscur: Expedition 33 Loses Indie Game Awards Honour Over Gen AI Use
  7. Realme Narzo 90x 5G Sale in India Begins Today
  8. Battle of the Nerds: Godfather of AI, Google DeepMind Chief Argue Over AGI
  9. How Much Water Does AI Use? Consumption Now Exceeds World's Bottled Water
  10. Paramount's New Offer for Warner Bros. Is Not Sufficient, Major Investor Says
  1. NASA’s SPHEREx Telescope Delivers First Full-Sky Map, Unlocking Cosmic Secrets
  2. Robotic Arm Achieves 1,000 Tasks in a Day Through Innovative Imitation Learning
  3. Ponies OTT Release Date: Know When to Watch This Emilia Clarke and Haley Lu Richardson starrer web series online
  4. Bhabhi Ji Ghar Par Hain 2.0 Now Streaming Online: What You Need to Know
  5. Paramount's New Offer for Warner Bros. Is Not Sufficient, Major Investor Says
  6. HMD Pulse 2 Specifications Leaked; Could Launch With 6.7-Inch Display, 5,000mAh Battery
  7. WhatsApp Begins Testing Support for Viewing Connected Peripherals
  8. OpenAI Tipped to Add Skills Feature to ChatGPT, Could Be Available as Slash Commands
  9. Is AGI Possible? Godfather of AI and Google DeepMind Chief Caught in War of Words on Social Media
  10. Honor Win Series Camera Specifications Tipped Days Ahead of China Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.