Android Lock Screens Can Easily Be Bypassed With New Exploit: Report

Advertisement
By NDTV Correspondent | Updated: 16 September 2015 20:33 IST

A new report by the University of Texas, Austin, has revealed an easy exploit hackers can use to bypass the lock screen of Android devices. The trick works on handsets running any OS version between Android 5.0 to Android 5.1.1 (but not the latest LMY48M build) with a password-based lock, even if encryption is enabled on the device. Google's latest Android distribution numbers peg the affected handsets at 21 percent of all active Android devices.

According to the study, hackers would first have to swipe left from the handset lock screen to open the camera app and access the 'Settings' page from the notifications panel. On tapping the Settings icon, the hacker would see the smartphone asking users to insert a password. The hacker can then dump a sufficiently long string of characters in the field, and as a result, the handset will crash to the home screen. "At this point arbitrary applications can be run or adb developer access can be enabled to gain full access to the device and expose any data contained therein," the report adds.

There are a few ways hackers could copy a large string of characters into the Android clipboard, and then paste it into the password prompt. The University of Texas study uses the emergency dialling field, and creates a long list of characters by copy-pasting a small sequence multiple times. The resultant long string can then be copied and pasted on the password prompt.

Advertisement

Fortunately, Google has addressed the particular vulnerability and last week started rolling out a fix as a part of its monthly Android security update with build number 'LMY48M', which featured several other fixes including for the Stagefright vulnerability. The fix for "Elevation of Privilege Vulnerability in Lockscreen (CVE-2015-3860)" has started rolling out to Nexus 4, Nexus 5, Nexus 6, Nexus 7, Nexus 9 and Nexus 10. However, it can take weeks or even months for the update to reach all the vulnerable Android devices. For those who want an immediate solution, they can switch to a PIN or pattern-based lock screen.

Advertisement

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Vivo V70 Series Could Cost in India
  2. iQOO 15 Ultra to Feature Shoulder Triggers, More Gaming Features
  3. Motorola Edge 70 Fusion Hits Geekbench With This Snapdragon Chipset
  4. Apple Sees Record Growth in iPhone Shipments in India
  5. Physicists Develop New Method to Detect Tiny Fluctuations in Spacetime
  6. Invincible Season 4 Is Arriving on OTT Soon
  7. Young Sherlock Now Set for OTT Release on OTT: All the Details
  8. Researchers Uncover Potential 9-Month 'Wobble' in Nearby Gas Giant
  1. VLT’s GRAVITY Instrument Detects ‘Tug’ from Colossal Exomoon; Could Be Largest Natural Satellite Ever Found
  2. Young Sherlock Now Set for OTT Release on OTT: What You Need to Know About Guy Ritchie’s Mystery Thriller
  3. NASA’s Miner++ AI Brings Machine Digs Into TESS Archive to the Hunt for Nearby Earth-Like Worlds
  4. iQOO 15 Ultra Confirmed to Feature Touch-based Shoulder Triggers With Haptic Feedback
  5. Invincible Season 4 OTT Release: When and Where to Watch the Highly Anticipated Viltrumite War Online?
  6. iPhone Shipments in India Rise to 14 Million Units in 2025 as Apple Sees Record Year: Report
  7. Oppo Find N6 Listed on TDRA Website, Hinting at Imminent Launch in the UAE
  8. NASA’s JWST Uncovers a ‘Feeding Frenzy’ That Births Supermassive Black Holes
  9. NASA Confirms Historic Artifacts Will Fly on Artemis II Moon Mission
  10. Hubble Reveals How Blue Straggler Stars Stay Young in Ancient Clusters
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.