Android Lock Screens Can Easily Be Bypassed With New Exploit: Report

Advertisement
By NDTV Correspondent | Updated: 16 September 2015 20:33 IST

A new report by the University of Texas, Austin, has revealed an easy exploit hackers can use to bypass the lock screen of Android devices. The trick works on handsets running any OS version between Android 5.0 to Android 5.1.1 (but not the latest LMY48M build) with a password-based lock, even if encryption is enabled on the device. Google's latest Android distribution numbers peg the affected handsets at 21 percent of all active Android devices.

According to the study, hackers would first have to swipe left from the handset lock screen to open the camera app and access the 'Settings' page from the notifications panel. On tapping the Settings icon, the hacker would see the smartphone asking users to insert a password. The hacker can then dump a sufficiently long string of characters in the field, and as a result, the handset will crash to the home screen. "At this point arbitrary applications can be run or adb developer access can be enabled to gain full access to the device and expose any data contained therein," the report adds.

There are a few ways hackers could copy a large string of characters into the Android clipboard, and then paste it into the password prompt. The University of Texas study uses the emergency dialling field, and creates a long list of characters by copy-pasting a small sequence multiple times. The resultant long string can then be copied and pasted on the password prompt.

Advertisement

Fortunately, Google has addressed the particular vulnerability and last week started rolling out a fix as a part of its monthly Android security update with build number 'LMY48M', which featured several other fixes including for the Stagefright vulnerability. The fix for "Elevation of Privilege Vulnerability in Lockscreen (CVE-2015-3860)" has started rolling out to Nexus 4, Nexus 5, Nexus 6, Nexus 7, Nexus 9 and Nexus 10. However, it can take weeks or even months for the update to reach all the vulnerable Android devices. For those who want an immediate solution, they can switch to a PIN or pattern-based lock screen.

Advertisement

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. GTA 6 PC System Requirements: Anticipated Specs, System Recommendations
  1. Engineers Turn Lobster Shells Into Robot Parts That Lift, Grip and Swim
  2. Strongest Solar Flare of 2025 Sends High-Energy Radiation Rushing Toward Earth
  3. Raat Akeli Hai: The Bansal Murders OTT Release: When, Where to Watch the Nawazuddin Siddiqui Murder Mystery
  4. Bison Kaalamaadan Is Now Streaming: Know All About the Tamil Sports Action Drama
  5. Pharma OTT Release: When, Where to Watch the Malayalam Medical Thriller Web Series
  6. Apple, Google and Samsung Reportedly Challenge India's New Proposal on Always-On Smartphone Location Tracking
  7. SpaceX Launches 28 New Starlink Satellites as Falcon 9 Hits Another Milestone
  8. Misaligned Exoplanet Is Challenging How We Think Solar Systems Form
  9. Indian Dance Mudras May Revolutionise Robotic Hand Control, UMBC Study Shows
  10. Mission: Impossible – The Final Reckoning Now Streaming Online: Watch Ethan Hunt's Final Quest on This OTT Platform
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.