Chrome Exploit Allegedly Gives Root Access to Virtually Any Android Device

Advertisement
By Manish Singh | Updated: 13 November 2015 17:49 IST

A critical vulnerability in Chrome for Android has been reported that makes it possible for attackers to take over a device. The vulnerability was demonstrated at the MobilePwn2Own, PacSec conference in Tokyo. The researcher believes that the vulnerability affects all versions of Android capable of running the latest version of Chrome.

Qihoo 360 researcher Guang Gong showcased the exploit. The vulnerability resides in JavaScript v8, Google's open source JavaScript engine. For the vulnerability to be exploited, users needs to be tricked to visit a malicious website using Chrome Web browser.

An attacker is then able to install an arbitrary application and gain the full privileges of the device. He noted that the attack was "one shot exploit," essentially meaning that just one vulnerability was enough to perform the attack. The exploit worked on many other devices as well, said Dragos Ruiu, the organiser of PacSec.

Advertisement

"The impressive thing about Guang's exploit is that it was one shot; most people these days have to exploit several vulnerabilities to get privileged access and load software without interaction," Ruiu told Vulture South.

Advertisement

"As soon as the phone accessed the website the JavaScript v8 vulnerability in Chrome was used to install an arbitrary application (in this case a BMX Bike game) without any user interaction to demonstrate complete control of the phone."

Working details of the vulnerability haven't been disclosed, and Ruiu said that Google had been made aware of the vulnerability.

Advertisement

At the same event, two security researchers managed to trick the Samsung Galaxy S6, Galaxy S6 Edge, and the Galaxy Note 4 to connect to a compromised base station and had the calls and messages go through it. As a result of which, a victim's calls and messages could be intercepted.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  2. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts
  3. OnePlus Ace 6T With Massive 8,300mAh Battery Launched at This Price
  4. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  5. Samsung Galaxy S26 vs Galaxy S25: Here Are the Anticipated Upgrades
  6. Redmi 15C 5G Launched in India With These Specifications
  7. Vivo X300 Pro Review: Flagship Mobile Photography. Redefined.
  8. Poco C85 5G With a 6,000mAh Battery Will Launch in India on This Date
  9. Redmi 15C 5G India Launch Today: Everything You Need to Know
  10. ChatGPT Might Soon Be Integrated With the Apple Health App
  1. Government Removes Sanchar Saathi Pre-Installation Mandate After Pushback
  2. OnePlus Ace 6T Launched With 8,300mAh Battery, Snapdragon 8 Gen 5 SoC: Price, Specifications
  3. ChatGPT Could Soon Be Integrated With Apple Health App: Report
  4. Apple's Foldable iPhone Reportedly at Pre-Production Stage, Might Feature Vapour Chamber Cooling
  5. Google Photos 2025 Recap Rolls Out With Your Most Memorable Photo and Video Moments
  6. Sony ILCE-7V Full-Frame Mirrorless Camera Launched in India With 33-Megapixel Exmor RS Sensor: Price, Specifications
  7. Google Pixel Phones Get AI Notification Summaries, New Parental Controls With Android 16 QPR2 Update
  8. Motorola Smartphones in India Now Support PhonePe's Indus Appstore
  9. Circle to Search Update Adds Spam Detection; Google Brings Urgent Call Notes, New Emoji to Android
  10. Bitcoin Surges Above $93,000 as Liquidity Boost, Institutional Access Lift Market Confidence
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.