Android Lock Screens Can Easily Be Bypassed With New Exploit: Report

Advertisement
By NDTV Correspondent | Updated: 16 September 2015 20:33 IST

A new report by the University of Texas, Austin, has revealed an easy exploit hackers can use to bypass the lock screen of Android devices. The trick works on handsets running any OS version between Android 5.0 to Android 5.1.1 (but not the latest LMY48M build) with a password-based lock, even if encryption is enabled on the device. Google's latest Android distribution numbers peg the affected handsets at 21 percent of all active Android devices.

According to the study, hackers would first have to swipe left from the handset lock screen to open the camera app and access the 'Settings' page from the notifications panel. On tapping the Settings icon, the hacker would see the smartphone asking users to insert a password. The hacker can then dump a sufficiently long string of characters in the field, and as a result, the handset will crash to the home screen. "At this point arbitrary applications can be run or adb developer access can be enabled to gain full access to the device and expose any data contained therein," the report adds.

There are a few ways hackers could copy a large string of characters into the Android clipboard, and then paste it into the password prompt. The University of Texas study uses the emergency dialling field, and creates a long list of characters by copy-pasting a small sequence multiple times. The resultant long string can then be copied and pasted on the password prompt.

Advertisement

Fortunately, Google has addressed the particular vulnerability and last week started rolling out a fix as a part of its monthly Android security update with build number 'LMY48M', which featured several other fixes including for the Stagefright vulnerability. The fix for "Elevation of Privilege Vulnerability in Lockscreen (CVE-2015-3860)" has started rolling out to Nexus 4, Nexus 5, Nexus 6, Nexus 7, Nexus 9 and Nexus 10. However, it can take weeks or even months for the update to reach all the vulnerable Android devices. For those who want an immediate solution, they can switch to a PIN or pattern-based lock screen.

Advertisement

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Tab S10 Lite With Exynos 1380 SoC Launched in India
  2. Flipkart's Big Billion Days Sale Samsung Galaxy S24 Ultra Deal Leaked
  3. Flipkart Big Billion Days: iPhone 16 Price to Drop to Its Lowest Ever
  4. iPhone 17 Series Available to Pre-Order in India: See Price, Offers
  5. Sony Xperia 10 VII Launched With 5,000mAh Battery and This Snapdragon Chip
  6. Moto Pad 60 Neo Launched in India: Check Price, Features
  7. OTT Releases This Week: An Action-Packed Weekend Awaits You With These Releases
  1. NASA Restores Contact With TRACERS Spacecraft SV1 After Communication Loss
  2. Mario Tennis Fever, Super Mario Galaxy 1+2, Donkey Kong Bananza DLC: Major Announcements at Nintendo Direct
  3. James Webb Space Telescope Spots Rare Protostar Blasting Twin Jets Across Milky Way
  4. Scientists Say Solar Flares Are Hotter Than Expected, Could Reach 108 Million Degrees
  5. Artiste OTT Release: This Is Where You Can Watch the Telugu-Language Crime Thriller
  6. Borderlands 4 Becomes Series' Biggest Steam Launch Ever With Over 200,000 Concurrent Players
  7. Meesha Is Now Streaming on Sun NXT: All About This Malayalam Survival Drama
  8. KuCoin Taps Golfer Adam Scott as First Global Brand Ambassador
  9. Poco M7 Plus 5G to Be Available in New 4GB RAM Variant in India on September 22
  10. Realme Could Be Working on Clip-Style Earbuds, Patent Application Shows
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.