Android bug opens devices to outside control

Advertisement
By Reuters | Updated: 5 June 2012 18:13 IST
Highlights
  • Bug discovered in Android's operating system can be used by hackers to gain control of the devices.
Cybersecurity experts have uncovered a flaw in a component of the operating system of Google Inc's widely used Android smartphone that they say hackers can exploit to gain control of the devices.

Researchers at startup cybersecurity firm CrowdStrike said they have figured out how to use that bug to launch attacks and take control of some Android devices.

CrowdStrike, which will demonstrate its findings next week at a major computer security conference in San Francisco, said an attacker sends an email or text message that appears to be from a trusted source, like the user's phone carrier. The message urges the recipient to click on a link, which if done infects the device.

At that point, the hacker gains complete control of the phone, enabling him or her to eavesdrop on phone calls and monitor the location of the device, said Dmitri Alperovitch, chief technology officer and co-founder of CrowdStrike.

Google spokesman Jay Nancarrow declined comment on Crowdstrike's claim.

Alperovitch said the firm conducted the research to highlight how mobile devices are increasingly vulnerable to a type of attack widely carried out against PCs. In such instances, hackers find previously unknown vulnerabilities in software, then exploit those flaws with malicious software that is delivered via tainted links or attached documents.

He said smartphone users need to prepare for this type of attack, which typically cannot be identified or thwarted by mobile device security software.

"With modifications and perhaps use of different exploits, this attack will work on every smartphone device and represents the biggest security threat on those devices," said Alperovitch, who was vice president of threat research at McAfee Inc before he co-founded CrowdStrike.

Researchers at CrowdStrike were not the first to identify such a threat, though such warnings are less common than reports of malicious applications that make their way to online websites, such as Apple's App Store or the Android Market.

In July 2009, researchers Charlie Miller and Collin Mulliner figured out a way to attack Apple's iPhone by sending malicious code embedded in text messages that was invisible to the phone's user. Apple repaired the bug in the software a few weeks after the pair warned it of the problem.

The method devised by CrowdStrike currently works on devices running Android 2.2, also known as Froyo. That version is installed on about 28 percent of all Android devices, according to a Google survey conducted over two weeks ending February 1.

Alperovitch said he expects to have a second version of the software finished by next week that can attack phones running Android 2.3. That version, widely known as Gingerbread, is installed on another 59 percent of all Android devices, according to Google.

CrowdStrike's method of attack makes use of a previously unpublicized security flaw in a piece of software known as webkit, which is built into the Android operating system's Web browser.

Webkit is also incorporated into other software programs, including Google's Chrome browser and the Apple iOS operating system for the iPhone and iPad.

CrowdStrike said it had not attempted to create software to attack iOS devices or the Chrome browser.

Manufacturers of Android devices include HTC Corp, LG Electronics Inc, Motorola Mobility Holdings Inc and Samsung Electronics Co.

Copyright Thomson Reuters 2012

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  2. iQOO Neo 11 With Snapdragon 8 Elite SoC Launched: Price, Specifications
  3. Realme GT 8 Pro India Launch Date Leaked: Here's When It Might Arrive
  4. iQOO 15 Indian Variant Allegedly Surfaces on Geekbench Ahead of Launch
  5. You Can Now Repair the iPhone 17 Series, iPhone Air Yourself in These Regions
  6. Lava Agni 4 With Metal Design and Flat Edges Teased Ahead of Debut
  7. Apple CEO Confirms Partnership Plans for AI Services Beyond OpenAI
  8. Canva Brings Revamped Video Editor, New AI Tools and a Marketing Platform
  9. Vivo X300 Series With 200-Megapixel Zeiss Camera Launched Globally
  10. Google, Magic Leap Unveil Android XR Glasses Prototype With In-Lens Display
  1. WhatsApp Announces Passkey-Encrypted Chat Backups With Biometric Authentication for Extra Security
  2. Apple CEO Tim Cook Forecasts Holiday Quarter iPhone Sales That Top Wall Street Estimates
  3. Realme GT 8 Pro India Launch Date Tipped After Company Confirms November Debut
  4. iPhone 17 Series, iPhone Air Join Apple’s Self Service Repair Programme Across US, Canada and Europe
  5. Google, Magic Leap Show Off New Android XR Glasses Prototype With In-Lens Display
  6. iQOO 15 Indian Variant Allegedly Surfaces on Geekbench With Snapdragon 8 Elite Gen 5 Chipset
  7. Apple CEO Reportedly Confirms Partnership Plans Beyond OpenAI; Revamped Siri Expected to Launch in 2026
  8. Scientists May Have Finally Solved the Sun’s Mysteriously Hot Atmosphere Puzzle
  9. Vivo X300 Series Launched Globally With 200-Megapixel Zeiss Camera, Up to 6.78-Inch Display: Price, Features
  10. Canva Introduces Revamped Video Editor, New AI Tools and a Marketing Platform
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.