Android Lock Screens Can Easily Be Bypassed With New Exploit: Report

Advertisement
By NDTV Correspondent | Updated: 16 September 2015 20:33 IST
Android Lock Screens Can Easily Be Bypassed With New Exploit: Report

A new report by the University of Texas, Austin, has revealed an easy exploit hackers can use to bypass the lock screen of Android devices. The trick works on handsets running any OS version between Android 5.0 to Android 5.1.1 (but not the latest LMY48M build) with a password-based lock, even if encryption is enabled on the device. Google's latest Android distribution numbers peg the affected handsets at 21 percent of all active Android devices.

According to the study, hackers would first have to swipe left from the handset lock screen to open the camera app and access the 'Settings' page from the notifications panel. On tapping the Settings icon, the hacker would see the smartphone asking users to insert a password. The hacker can then dump a sufficiently long string of characters in the field, and as a result, the handset will crash to the home screen. "At this point arbitrary applications can be run or adb developer access can be enabled to gain full access to the device and expose any data contained therein," the report adds.

There are a few ways hackers could copy a large string of characters into the Android clipboard, and then paste it into the password prompt. The University of Texas study uses the emergency dialling field, and creates a long list of characters by copy-pasting a small sequence multiple times. The resultant long string can then be copied and pasted on the password prompt.

Fortunately, Google has addressed the particular vulnerability and last week started rolling out a fix as a part of its monthly Android security update with build number 'LMY48M', which featured several other fixes including for the Stagefright vulnerability. The fix for "Elevation of Privilege Vulnerability in Lockscreen (CVE-2015-3860)" has started rolling out to Nexus 4, Nexus 5, Nexus 6, Nexus 7, Nexus 9 and Nexus 10. However, it can take weeks or even months for the update to reach all the vulnerable Android devices. For those who want an immediate solution, they can switch to a PIN or pattern-based lock screen.

Advertisement

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 3 Rear Panel Revealed in New Teaser Ahead of June 1 Launch
  2. OTT Releases This Week: Pattth, Stolen, Jaat, Bhool Chuk Maaf, and More
  3. iQOO Z10 Lite 5G India Launch Date, Design and Battery Size Confirmed
  4. Top Smartphones Under Rs. 15,000 in India (June 2025): Check List
  5. Oppo K13x 5G India Launch Teased; to Go on Sale via Flipkart
  1. Google Chrome Gets 'Highest Ever' Speedometer Score; Company Reveals Optimisations Behind Improved Performance
  2. Nothing Phone 3 Rear Panel Design Teased; Suggests Departure From Signature Glyph Design
  3. Xiaomi Smart Band 10 Leaked Marketing Images Suggest Design and Key Features
  4. 'We're Not Done Yet': CD Projekt Red Confirms Cyberpunk 2077 Is Getting Another Update Later This Month
  5. Microsoft Introduces Copilot Shopping With Native Checkout Capability in App
  6. Vivo Y-Series Smartphone With Curved Display Said to Launch in India; Colour Options Leaked
  7. Uber Reportedly Exploring Stablecoin Adoption to Cut Cross-Border Transfer Costs
  8. Perplexity AI CEO Pans Google’s AI Rollout and Assistant Product
  9. Tecno Pova 7 Neo 4G Design Spotted in Leaked Hands-On Images; Key Features Surface Online
  10. PhonePe to Launch UPI Payments App for Feature Phones With P2P Transfers, Offline QR Payments
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.