Android Mediaserver Bug Can Render Devices Unresponsive: Trend Micro

Advertisement
By Ketan Pratap | Updated: 30 July 2015 16:39 IST
Soon after Google announced a security update for the Stagefright vulnerability (a critical security bug) for its Nexus devices, a new bug has been reported that security researchers claim leaves Android device "dead."

Trend Micro's Wish Wu, a mobile threat response engineer, has detailed the newly discovered vulnerability in the Android mobile operating system. According to the report, the vulnerability renders the Android device unresponsive - "silent, unable to make calls, with a lifeless screen."

The vulnerability is said to be present from Android 4.3 Jelly Bean to the current version, Android 5.1.1 Lollipop. It's worth noting that majority of Android devices, almost 90 percent, are currently running these versions, according to the Google's Android distribution numbers.

Advertisement

Wu explains the process, "The vulnerability lies in the mediaserver service, which is used by Android to index media files that are located on the Android device. This service cannot correctly process a malformed video file using the Matroska container (usually with the .mkv extension). When the process opens a malformed MKV file, the service may crash (and with it, the rest of the operating system)."

Further explaining, Trend Micro notes that the vulnerability can be exploited in two ways either via an installed malicious app on the device or through a specially-crafted website.

Advertisement

"The first technique can cause long-term effects to the device: an app with an embedded MKV file that registers itself to auto-start whenever the device boots would case the OS to crash every time it is turned on," notes the report.

Some of the implication of the vulnerability is said to be unresponsive UI and even claims that if the phone is locked, it cannot be unlocked. Trend Micro speculates some of the potential threat scenarios where it claims attackers can use it for ransomware. However, it's worth noting that once the device is unresponsive; how the attackers will ask for ransom from affected Android users.

Advertisement

Trend Micro notes that the vulnerability was privately reported to Google in May. The company acknowledged the report however marked the issue as a low priority vulnerability. A Google spokesperson told Engadget that the "future version of Android" would patch the vulnerability while stressed that there has been "no evidence of actual exploitation."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Apps, Google, Malware, Trend Micro
Advertisement

Related Stories

Popular Mobile Brands
  1. iOS 27 Release Date and How to Update: Supported iPhones
  2. Samsung Galaxy Z Fold 8 Ultra Listed on BIS Database, May Launch Soon
  3. Samsung Galaxy Watch 8 Gets More Secure With Latest Wear OS Patches
  4. OnePlus 15 Reportedly Gains AirDrop Support Through Quick Share
  5. Honor's Next X-Series Phone Could Arrive With a Massive 11,000mAh Battery
  6. Samsung Galaxy Tab Active 6 Reportedly in Development for 2027 Debut
  7. Apple Unveils iOS 27 With Revamped Siri and Liquid Glass Improvements
  8. Xbox Users Can Expect 'Reliable Pipeline' of Console Exclusive Games
  9. Lava Bold N2 5G Goes on Sale in India With 6,000mAh Battery: Price, Offers
  10. Oppo Reno 16 Indian Variant Surfaces on Benchmarking Site Ahead of Debut
  1. Stellar Blade: Blood Rain Protagonist Will Have More of a Personality, Says Shift Up
  2. Samsung Galaxy Tab Active 6 Reportedly Set to Launch in 2027 With 5G Connectivity
  3. iOS 27 Finally Adds Separate Volume Controls for Ringtones and Alarms, Just Like Android Phones
  4. UK Regulator Proposes Allowing Retail Funds to Hold Up to 10 Percent in Crypto ETNs
  5. Samsung Galaxy Z Fold 8 Ultra Reportedly Listed on BIS Database, Tipster Leaks Key Specifications
  6. Redmi Note 17 Visits EEC Certification Database Along With a New Vivo Handset, Hinting at Imminent Global Launch
  7. OnePlus 15 Gains AirDrop Support via Quick Share as Google Expands Availability Beyond Pixel, Samsung Phones
  8. Apple Will Soon Allow Android, Windows Users to Share Photos to iCloud Shared Albums
  9. WhatsApp Claims NSO Group-Linked Entity Unsuccessfully Carried Out Fresh Phishing Attacks Against Users
  10. Oppo Reno 16 Indian Variant Listed on Geekbench With Snapdragon 7 Gen 4 Chip, Android 16
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.