Google Fixes Critical PNG Security Bug, but Millions of Android Smartphones Still Vulnerable

Advertisement
By Nadeem Sarwar | Updated: 7 February 2019 19:16 IST
Highlights
  • The vulnerability affects Android 7.0 and above versions
  • It can be exploited by a specially crafted PNG file
  • No reports of the vulnerability being exploited so far

The critical vulnerability has been fixed by the February 2019 Android security update

Google recently began the rollout of the February 2019 Android security update that addresses a total of 42 issues and fixes vulnerabilities of varying severity levels. But if you think this is just a regular security update, you might want to reconsider. One of the vulnerabilities fixed by Google could allow a hacker to seed malware by just sending a photo in PNG format. And as soon as users open the image, it triggers the exploit and allows bad actors to remotely execute arbitrary code and wreak havoc.

This is how Google describes it, saying in its February Android 2019 security patch notes, "The most severe of these issues is a critical security vulnerability in Framework that could allow a remote attacker using a specially crafted PNG file to execute arbitrary code within the context of a privileged process." But despite Google having identified and fixed the issue, there is little respite for the millions of Android smartphone users out there. Why? Well, the February 2019 Android security update has only been released for the Pixel smartphones, the Pixel C tablet, and the Essential Phone. Needless to say, the number of Pixel devices out there is seemingly nothing compared to the millions of Android smartphones from other brands. To further aggravate the issue, a majority of at-risk users have not been notified as to when their Android smartphone will receive the February 2019 Android security update and safeguard them.

So, what can be done in this case? The best solution is to not open an image, specifically a PNG file received via an untrusted email, SMS, or on a messaging platform. The focus here is on a PNG file, because the critical vulnerability can be exploited via a specially crafted PNG file to execute arbitrary code within the context of a privileged process. To simply put it, opening the infected PNG file will activate the exploit and could open the floodgates for downloading malware on the device.

Advertisement

The critical vulnerability has been spotted in three forms (CVE-2019-1986, CVE-2019-1987, and CVE-2019-1988) and affects Android smartphones running Android 7.0 or a higher build going all the way up to Android Pie. Google claims that so far, no incidents of bad actors exploiting the critical security bug have been reported so far. Moreover, Google has already notified all Android partners about the security bug one month prior to publishing details of the vulnerabilities and has also released the code patches to the Android Open Source Project (AOSP) repository.

Advertisement

While Pixel users have received an update to patch the critical vulnerability, other smartphone makers are yet to release an update to address the issue on their offerings. Until that happens, we advise you to refrain from opening PNG files received from unknown people and download the security update as soon as it becomes available.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series India Launch Date, Price Range Leaked
  2. Realme 16 Pro Series Camera Details and Realme Buds Air Launch Date Revealed
  3. Xiaomi 17 Ultra's Leica Camera Confirmed to Support Continuous Optical Zoom
  4. Xiaomi 17 Ultra, Poco X8 Pro Spotted on IMDA Ahead of Global Launch
  5. Motorola Edge 70 Goes on Sale in India: See Price, Offers, Features
  6. Google Brings Its Emergency Location Service to Smartphones in India
  7. Paramount's New Offer for Warner Bros. Is Not Sufficient, Major Investor Says
  8. Battle of the Nerds: Godfather of AI, Google DeepMind Chief Argue Over AGI
  9. HMD Pulse 2 Key Specifications Leaked Online
  10. Realme Narzo 90x 5G Sale in India Begins Today
  1. Paramount's New Offer for Warner Bros. Is Not Sufficient, Major Investor Says
  2. HMD Pulse 2 Specifications Leaked; Could Launch With 6.7-Inch Display, 5,000mAh Battery
  3. WhatsApp Begins Testing Support for Viewing Connected Peripherals
  4. OpenAI Tipped to Add Skills Feature to ChatGPT, Could Be Available as Slash Commands
  5. Is AGI Possible? Godfather of AI and Google DeepMind Chief Caught in War of Words on Social Media
  6. Honor Win Series Camera Specifications Tipped Days Ahead of China Launch
  7. Oppo Reno 15 Series India Launch Date, Price Range Surface Online; Tipster Leaks Global Variant Price, Features
  8. Clair Obscur: Expedition 33's Game of the Year Win at Indie Game Awards Retracted Over Gen AI Use
  9. Xiaomi 17 Ultra, Poco X8 Pro Listed on IMDA Database; Global Debut Expected Soon After Launch in China
  10. How Much Water Does AI Use? Consumption Now Exceeds World’s Bottled Water, Suggests New Study
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.