Android's Full Disk Encryption Compromised, Affects Millions of Devices

Advertisement
By Roydon Cerejo | Updated: 4 July 2016 14:01 IST
Highlights
  • Researcher Gal Beniamini, found a way to compromise Android's FDE
  • The hack leaves millions of Android devices at risk of being vulnerable
  • Google and Qualcomm are aware of the issue and have released patches

It's far from surprising anymore to hear about security glitches in Android but this latest find could potentially compromise the security of hundreds of millions of devices. The flaw has been spotted by Gal Beniamini, a security researcher, who's found a way to use ARM's TrustZone kernel code-execution to essentially break Android's Full Disk Encryption (FDE).

All Android smartphones running on 5.0 Lollipop or later use something called FDE, which makes all the data on your phone unreadable unless you have the unique key needed to decrypt it. This is the similar to the security feature that caused a tussle between the FBI and Apple recently. According to Beniamini's report, an attacker can potentially exploit certain loopholes in Qualcomm's security in order to recover that unique encryption key. He also states that the issue cannot be completely resolved with merely a security patch as it might require hardware changes.

Advertisement

FDE is designed to be uncrackable but clearly it's not as secure as Google hoped. Breaking FDE still requires a brute-force attack but once the attacker has the key, all that's left is figuring out your password. Beniamini's research also found that the key is not hardware bound which means it can be extracted by software. He goes on to state that Android's current FDE is only as strong as the TrustZone kernel. Any vulnerability exploited here could easily compromise the devices encryption and thereby, exposing your private data.

Google says it rolled out patches for this issue earlier this year. Qualcomm says the issue was "identified internally" and fixed, with patches issued to "customers and partners", but if and when these fixes find their way down to consumer devices out there is anyone's guess.

Advertisement

Qualcomm's full statement: "Providing technologies that support robust security and privacy is a priority for Qualcomm Technologies, Inc. (QTI). QTI continues to work proactively both internally as well as with security researchers such as Gal Beniamini to identify and address potential security vulnerabilities. The two security vulnerabilities (CVE-2015-6639 and CVE-2016-2431) discussed in Beniamini's June 30 blog post were also discovered internally and patches were made available to our customers and partners. We have and will continue to work with Google and the Android ecosystem to help address security vulnerabilities and to recommend improvements to the Android ecosystem to enhance security overall."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple May Have Just Given Us a Sneak Peek at Its Foldable iPhone
  2. Vivo Y31s Launched in Malaysia With These Features
  3. Apple's Airpods Will Finally Gain Custom EQ Support With iOS 27
  4. OnePlus Could Launch a New Budget Smartphone Lineup in India Soon
  5. Redmi Turbo 5 Battery, Camera Details Teased Ahead of Launch
  6. Apple Unveils iOS 27 With Revamped Siri and Liquid Glass Improvements
  7. iOS 27 Release Date and How to Update: Supported iPhones
  8. Bitcoin Holds Above $63,000 as Institutional Buying Lifts Sentiment
  1. Apple's First iOS 27 Beta Reportedly Contains Various Clues About Its Purported Foldable iPhone
  2. Honor X80 Pro Max in Development With Snapdragon 6 Gen 5 SoC and 11,000mAh Battery, Tipster Claims
  3. Redmi Turbo 5 India Variant to Feature Slightly Smaller Battery Than Chinese Version
  4. WWDC 2026: Apple Announces Custom EQ Feature for AirPods With iOS 27 Update
  5. Samsung Galaxy Watch 8, Watch 7 Get May 2026 Wear OS Update With Security Fixes
  6. Bitcoin Holds Above $63,400 as Institutional Buying Counters ETF Outflow Pressure
  7. Gears of War: E-Day, Clockwork Revolution Not 'One-Off', More Xbox Exclusives on Their Way
  8. WWDC 2026: Apple Showcases New Developer Tools for Improved App Store Discovery and Marketing
  9. Apple's iOS 27 Update to Arrive With Major Performance Upgrades for iPhone Including Faster AirDrop, App Launches and Search
  10. WWDC 2026: Apple Brings Visual Intelligence to Siri, Lets Users Access AI Information via iPhone Camera
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.