Google's Android Stagefright Security Patch Is Flawed, Says Researcher

Advertisement
By NDTV Correspondent | Updated: 14 August 2015 13:20 IST
Android's Stagefright vulnerability has received its share of concerns and patch release announcements from various Android OEM manufacturers, including a new monthly security update cycle. The problem however seems to still be around even after Google released a patch this month for its Nexus devices that was claimed to fix the Stagefright bug.

Jordan Gruskovnjak, a security researcher from Exodus Intelligence has discovered 'severe' problems with patch rolling out to Nexus devices. Jordan also claimed that the Stagefright Detector app released by Zimperium (the company that reported the issue initially) is unable to detect the flaw that remains after the patch, which just contains four lines of code.

"Despite our notification (and their confirmation), Google is still currently distributing the faulty patch to Android devices via OTA updates," notes Exodus Intelligence.

To recall, Stagefright is an open source media player and which is believed to be used on about 95 percent of Android devices, an estimated 950 million users. The vulnerability, if exploited, can let attackers take control of an Android device by sending a specially crafted media file delivered by an MMS message.

Advertisement

"Along with the initial bug report, a set of patches to stagefright flaws were supplied and accepted by Google. One of these patches, addressing CVE-2015-3824 (aka Google Stagefright 'tx3g' MP4 Atom Integer Overflow) was quite simple, consisting of merely 4 lines of changed code," notes Exodus Intelligence official blog.

Advertisement

Jordan tested out a Nexus 5 with an updated firmware flashed to it and was greeted with a crash upon testing. He was able to test the flaw through a specially-crafted mp4 file that bypassed the patch.

The security research company says that it notified Google, and was told the Mountain View company has allocated the CVE identifier CVE-2015-3864 to its report. The company claims that it had to make the issue public with their findings to notify everybody about the issue.

Advertisement

Google confirmed the findings to The Verge, and added that a second patch was already being pushed out. "We've already sent the fix to our partners to protect users, and Nexus 4/5/6/7/9/10 and Nexus Player will get the OTA update in the September monthly security update," said Google in a statement.

The company however did not comment when non-Nexus devices can expect to receive the patch.

Advertisement

Last week, Google and Samsung announced they will offer a monthly security patch to their devices. LG and Motorola also joined to reveal Stagefright vulnerability patches.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. Nothing Phone 3a Lite Goes on Sale in India at This Price
  3. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  4. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  5. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  6. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  7. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  8. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  9. Airtel Discontinues These Prepaid Recharge Packs in India
  10. NotebookLM App Now Has an In-Built Camera
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  4. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  5. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  6. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  7. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  8. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  9. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  10. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.