Android Lock Screens Can Easily Be Bypassed With New Exploit: Report

Advertisement
By NDTV Correspondent | Updated: 16 September 2015 20:33 IST

A new report by the University of Texas, Austin, has revealed an easy exploit hackers can use to bypass the lock screen of Android devices. The trick works on handsets running any OS version between Android 5.0 to Android 5.1.1 (but not the latest LMY48M build) with a password-based lock, even if encryption is enabled on the device. Google's latest Android distribution numbers peg the affected handsets at 21 percent of all active Android devices.

According to the study, hackers would first have to swipe left from the handset lock screen to open the camera app and access the 'Settings' page from the notifications panel. On tapping the Settings icon, the hacker would see the smartphone asking users to insert a password. The hacker can then dump a sufficiently long string of characters in the field, and as a result, the handset will crash to the home screen. "At this point arbitrary applications can be run or adb developer access can be enabled to gain full access to the device and expose any data contained therein," the report adds.

There are a few ways hackers could copy a large string of characters into the Android clipboard, and then paste it into the password prompt. The University of Texas study uses the emergency dialling field, and creates a long list of characters by copy-pasting a small sequence multiple times. The resultant long string can then be copied and pasted on the password prompt.

Advertisement

Fortunately, Google has addressed the particular vulnerability and last week started rolling out a fix as a part of its monthly Android security update with build number 'LMY48M', which featured several other fixes including for the Stagefright vulnerability. The fix for "Elevation of Privilege Vulnerability in Lockscreen (CVE-2015-3860)" has started rolling out to Nexus 4, Nexus 5, Nexus 6, Nexus 7, Nexus 9 and Nexus 10. However, it can take weeks or even months for the update to reach all the vulnerable Android devices. For those who want an immediate solution, they can switch to a PIN or pattern-based lock screen.

Advertisement

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  2. TRAI, DoT Approve Presentation of Caller Names During Incoming Calls
  3. WhatsApp Might Soon Let You Set a Profile Cover Photo, Just Like Facebook
  4. Moto G67 Power 5G India Launch Date, Key Features Announced
  5. iQOO 15 Colourways, Key Features Teased Ahead of Launch in India
  6. Nothing Phone 3a Lite Launch Today: Everything You Need to Know
  7. Oppo Find X9 Series With Hasselblad-Tuned Cameras Launched Globally
  8. Samsung Will Let You Unlock Your Mahindra e-SUV With Your Phone
  9. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  10. US Senators Want to Ban Teenagers From Using AI Chatbots
  1. Amazon Fire TV Stick 4K Select Launched in India With Vega OS: Price, Features
  2. AI Chatbots Will Be Banned for Teenagers With Mandatory Age Verification, Says Proposed US Law
  3. Visa to Add Support for Four Stablecoins Across Four Blockchains as Usage Surges
  4. Samsung Wallet Announces Support for Unlocking Mahindra e-SUV Using Smartphones
  5. Apple Shares Massive Dataset to Help Researchers Build Nano Banana-Like AI Models
  6. Microsoft CEO Satya Nadella Suggests Next-Gen Xbox Will Be Windows PC and Console Hybrid
  7. iQOO 15 Colourways, Key Specifications Teased Days Ahead of Launch in India
  8. Oppo Find X9, Find X9 Pro Confirmed to Be Available in India via Flipkart
  9. OpenAI Plans to Launch Automated 'AI Researcher' For Autonomous Scientific Discoveries by 2028
  10. Moto G67 Power to Come With 7,000mAh Battery, 50-Megapixel Sony Camera; India Launch Date Announced
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.