Android Flaw Lets Hackers Break in With an MMS: Report

Advertisement
By Agence France-Presse | Updated: 28 July 2015 10:24 IST
Cyber-security firm Zimperium on Monday warned of a flaw in the world's most popular smartphone operating system that lets hackers take control with a text message.

"Attackers only need your mobile number, using which they can remotely execute code via a specially crafted media file delivered via MMS (text message)," Zimperium Mobile Security said in a blog post.

"A fully weaponised successful attack could even delete the message before you see it. You will only see the notification."

Android code dubbed "Stagefright" was at the heart of the problem, according to Zimperium.

Advertisement

Stagefright automatically pre-loads video snippets attached to text messages to spare recipients from the annoyance of waiting to view clips.

Advertisement

Hackers can hide malicious code in video files and it will be unleashed even if the smartphone user never opens it or reads the message, according to research by Zimperium's Joshua Drake.

"The targets for this kind of attack can be anyone," the cyber-security firm said, referring to Stagefright as the worst Android flaw discovered to date.

Advertisement

"These vulnerabilities are extremely dangerous because they do not require that the victim take any action to be exploited."

Malicious code executed by hackers could take control of smartphones and plunder contents without owners knowing.

Advertisement

Stagefright imperils some 95 percent, or an estimated 950 million, of Android phones, according to the security firm.

Zimperium said that it reported the problem to Google and provided the California Internet firm with patches to prevent breaches.

"Google acted promptly and applied the patches to internal code branches within 48 hours, but unfortunately that's only the beginning of what will be a very lengthy process of update deployment," Zimperium said.

It did not appear as though hackers had taken advantage of the Stagefright vulnerability, according to Zimperium.

Updating Android software powering mobile devices is controlled by hardware makers and sometimes telecommunication service carriers, not Google.

While Apple controls the hardware and software in iPhones, iPads, and iPods powered by its mobile operating system, Google makes Android available free to device makers who customize the code and update it as they see fit.

More about Drake's research was to be disclosed at a Black Hat computer security conference taking place in Las Vegas early in August.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. Jolla Phone Launched With 5,500mAh Replaceable Battery, Sailfish OS 5
  3. OnePlus Pad Go 2 First Impressions
  4. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  5. Vivo S50, Vivo S50 Pro Mini Set to Launch on This Date
  6. OpenAI's Code Red: 5 Things to Know About the AI Giant's ChatGPT Strategy
  7. Nothing Halts Android 16 Rollout to Implement 'Urgent' Fix
  8. Elon Musk Confirms Grok 4.20 Release Timeline: Know Potential Launch Date
  9. Battlefield 6's Next Season 1 Update Arrives This Week: All You Need to Know
  1. Poco C85 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Scientists Unveil Screen That Produces Touchable 3D Images Using Light-Activated Pixels
  3. SpaceX Expands Starlink Network With 29-Satellite Falcon 9 Launch
  4. Nancy Grace Roman Space Telescope Fully Assembled, Launch Planned for 2026–2027
  5. Hell’s Paradise Season 2 OTT Release Date: When and Where to Watch it Online?
  6. Francis Lawrence’s The Long Walk (2025) Now Available for Rent on Prime Video and Apple TV
  7. Nicolas Cage Starrer Spider-Noir Set to Release on Prime Video in 2026
  8. Devi Chowdhurani OTT Release Date: When and Where to Watch Srabanti Chatterjee’s Period Drama Online?
  9. OnePlus Pad Go 2 Key Specifications and Sale Date Revealed; Will Feature Dimensity 7300-Ultra SoC
  10. OpenAI Claims Increased Enterprise Usage Amid CEO’s Code Red Declaration
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.