Millions on Android Devices Exposed by Unpatched Apple Lossless Codec Flaw: Researchers

The flaw allowed hackers to remotely execute code, potentially allowing them to snoop on Android users.

Advertisement
By David Delima | Updated: 22 April 2022 19:52 IST
Highlights
  • Researchers found flaws with the Apple Lossless Audio Codec (ALAC)
  • Apple open-sourced the code for ALAC in 2011 but the flaws were unpatched
  • Qualcomm and MediaTek issued patches fixing the flaws in December 2021

Android phones that received the December 2021 security patches are no longer vulnerable

Photo Credit: Reuters

Security flaws in an audio codec have been uncovered by security researchers, putting millions of Android phones and other Android devices powered by chipsets from MediaTek and Qualcomm at risk of being compromised by hackers. Stemming from an codec created by Apple several years ago, the vulnerabilities were left unpatched since the company open-sourced the codec 11 years ago, for inclusion on non-Apple devices. By leveraging the security flaws, an attacker could remotely get access to an Android phone's media and audio conversations, according to the researchers.

According to a report by researchers at Check Point Research, a flaw in the Apple Lossless Audio Codec (ALAC) from Apple allows an attacker to perform a remote code execution (RCE) attack on a target smartphone, after sending a malformed audio file. An RCE attack can allow the attacker to gain control of multimedia on the handset, including streaming video from the cameras, accessing media and user conversations.

Advertisement

The security flaws were discovered in Apple's ALAC codec, which was open-sourced by the company in 2011 — allowing non-Apple devices to stream music in ‘lossless' quality using Apple's previously proprietary codec. However, while Apple patched the proprietary version of the ALAC codec, the open-source version remained unpatched, according to the researchers.

As a result, Qualcomm and MediaTek, chipset manufacturers who ported the vulnerable ALAC codec to their audio decoders, resulting in over two thirds of all smartphones sold in 2021 being vulnerable to the security flaws, dubbed “ALHACK”, according to the researchers. The vulnerabilities were responsibly disclosed to Qualcomm and MediaTek, who both acknowledged the issues and assigned Common Vulnerabilities and Exposures (CVE) for the flaws. MediaTek assigned CVE-2021-0674 and CVE-2021-0675 (with ‘Medium' and ‘High' ratings, respectively), while Qualcomm assigned CVE-2021-30351 (with a ‘Critical' rating of 9.8 out of 10) for the ALAC flaws, before patching them.

Advertisement

According to the researchers, both companies have issued patches for the flaws included in the December 2021 Android security bulletin, which means that users with smartphones that received the December security patches should be safe from the vulnerabilities. However, this leaves out millions of users running outdated software, or users who receive erratic security updates — putting them at risk of being compromised by attackers.


Should you buy a 4G or 5G budget phone? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Durability, Battery Life Now Drive Smartphone Buying Decisions in India
  2. Sony Bravia 3II Series Debuts in India With a 120Hz 4K Display: See Prices
  3. Here's When the Realme 16T 5G Will Launch in India
  4. Amazon Great Summer Sale 2026: Best Deals on Vivo and iQOO Smartphones
  5. SanDisk Crayola USB Type-C Flash Drive Launched in India
  6. Sony's 'The ColleXion Headphones' Might Arrive With This Redesigned Hinge
  7. CMF Watch 3 Pro Review: Is It Worth the Price?
  8. Oppo Reno 16, Reno 16 Pro Could Arrive in These Colour Options
  1. Indian Smartphone Buyers Prioritise Durability, Long-Term Reliability Over Specifications, Study Finds
  2. Samsung Announces One UI 9 Beta With Redesigned Quick Panel, New Features in Notes App
  3. The Android Show I/O Edition: Know the Biggest Announcements Made at the Google Event
  4. The Android Show I/O Edition: Google Showcases Gemini Intelligence on Android With New AI-Backed Widget Creation Tool
  5. Google Unveils New Googlebook Laptops With Gemini Intelligence, Magic Pointer and Glowbar Design
  6. Artemis 2 Commander Reid Wiseman Teams Up With Astrophotographer for Rare Lunar Mission Photos
  7. Sony's Upcoming 'The ColleXion Headphones' Spotted With Revamped Hinge Mechanism in New Leak
  8. EBay Spurns GameStop’s Bid as ‘Neither Credible nor Attractive’
  9. Google's Android Show I/O Edition: How to Watch Livestream, What to Expect
  10. Sony Bravia 3II Lineup Launched in India With XR Processor, 120Hz 4K Display: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.