Google Fixes Critical PNG Security Bug, but Millions of Android Smartphones Still Vulnerable

Advertisement
By Nadeem Sarwar | Updated: 7 February 2019 19:16 IST
Highlights
  • The vulnerability affects Android 7.0 and above versions
  • It can be exploited by a specially crafted PNG file
  • No reports of the vulnerability being exploited so far

The critical vulnerability has been fixed by the February 2019 Android security update

Google recently began the rollout of the February 2019 Android security update that addresses a total of 42 issues and fixes vulnerabilities of varying severity levels. But if you think this is just a regular security update, you might want to reconsider. One of the vulnerabilities fixed by Google could allow a hacker to seed malware by just sending a photo in PNG format. And as soon as users open the image, it triggers the exploit and allows bad actors to remotely execute arbitrary code and wreak havoc.

This is how Google describes it, saying in its February Android 2019 security patch notes, "The most severe of these issues is a critical security vulnerability in Framework that could allow a remote attacker using a specially crafted PNG file to execute arbitrary code within the context of a privileged process." But despite Google having identified and fixed the issue, there is little respite for the millions of Android smartphone users out there. Why? Well, the February 2019 Android security update has only been released for the Pixel smartphones, the Pixel C tablet, and the Essential Phone. Needless to say, the number of Pixel devices out there is seemingly nothing compared to the millions of Android smartphones from other brands. To further aggravate the issue, a majority of at-risk users have not been notified as to when their Android smartphone will receive the February 2019 Android security update and safeguard them.

So, what can be done in this case? The best solution is to not open an image, specifically a PNG file received via an untrusted email, SMS, or on a messaging platform. The focus here is on a PNG file, because the critical vulnerability can be exploited via a specially crafted PNG file to execute arbitrary code within the context of a privileged process. To simply put it, opening the infected PNG file will activate the exploit and could open the floodgates for downloading malware on the device.

Advertisement

The critical vulnerability has been spotted in three forms (CVE-2019-1986, CVE-2019-1987, and CVE-2019-1988) and affects Android smartphones running Android 7.0 or a higher build going all the way up to Android Pie. Google claims that so far, no incidents of bad actors exploiting the critical security bug have been reported so far. Moreover, Google has already notified all Android partners about the security bug one month prior to publishing details of the vulnerabilities and has also released the code patches to the Android Open Source Project (AOSP) repository.

Advertisement

While Pixel users have received an update to patch the critical vulnerability, other smartphone makers are yet to release an update to address the issue on their offerings. Until that happens, we advise you to refrain from opening PNG files received from unknown people and download the security update as soon as it becomes available.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  2. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  3. Gaming-Focused OnePlus Turbo Series Confirmed to Launch Soon
  4. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  5. Oppo Find X9 Ultra Battery Capacity Teased By Company Executive
  6. Honor Power 2 Key Features Leaked; Could Launch With a 10,080mAh Battery
  7. Hollow Knight: Silksong's First Expansion, Sea of Sorrow, Is Coming Next Year
  1. Global Smartphone Shipments to Slightly Shrink in 2026 Due to RAM Shortage, Higher Component Costs: Report
  2. Dead Island 3 Is in Development at Dambuster Studios; Launch Planned for 2028
  3. Google and ChatGPT Remain the Most Popular Services as Internet Traffic Grows by 19 Percent: Cloudflare
  4. HyperOS 3 Update Rolls Out to Xiaomi 14, Redmi Note 14 5G and More Devices With Android 16, New AI Features
  5. iOS 26.3 Beta 1 Reportedly Adds Transfer Tool for Switching to Android, Notification Forwarding for Wearables
  6. OpenAI Hires New Head of App Platform to Turn ChatGPT Into an Operating System
  7. Honor Power 2 Chipset, Display Specifications Tipped; Could Launch With 10,080mAh Battery
  8. Hollow Knight: Silksong's First Major Expansion, Sea of Sorrow, Announced; Launch Set for 2026
  9. Oppo Find X9 Ultra Battery Capacity Teased By Company Executive: Here's What We Know So Far
  10. Dhruv64: India’s First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.