Linux Vulnerability Leaves 1.4 Billion Android Devices Open to Security Threat: Report

Advertisement
By Shekhar Thakran | Updated: 16 August 2016 20:22 IST
Highlights
  • The security flaw reportedly exists on 80 percent of Android devices
  • The flaw was revealed USENIX Security 2016 conference recently
  • Lookout has suggested use of VPN to avoid being spied upon

Just when you might be wrapping your head around that QuadRooter saga, researchers from mobile security firm Lookout have suggested that a newly discovered Linux flaw essentially "allows an attacker to remotely spy on people who are using unencrypted traffic or degrade encrypted connections."

The Linux kernel vulnerability, which was revealed recently in TCP at the USENIX Security 2016 conference, was introduced in version 3.6 of the Linux OS kernel (released in 2012) and exists in all Android smartphones running version 4.4 KitKat or later, as pointed out in the security firm's blog post.

Advertisement

As Lookout points out, that's 80 percent of Android devices according to Google's latest distribution figures, or roughly 1.4 billion devices, based on Statista's figures.

The vulnerability means that attackers would be able to detect communications over a TCP connection, and if unencrypted, even insert malicious code into that traffic. "While a man in the middle attack is not required here, the attacker still needs to know a source and destination IP address to successfully execute the attack," Lookout said in its blog. Lookout has suggested that Android users should consider using VPN while browsing and also encrypt the communications to prevent them from being spied on.

Advertisement

As the exploit is relatively hard to execute, Lookout has assigned medium severity rating to the flaw but does clarify that the risk of "targeted attacks" is there. The underlying Linux OS kernel vulnerability is classified as CVE-2016-5696, and has been patched.

The security firm has said that even though the patch for the Linux kernel was created on July 11, with the latest developer preview of Android 7.0 Nougat, the kernel doesn't seem to be patched against this particular flaw.

Advertisement

Speaking to Ars Technica, a Google representative said the company was aware of the vulnerability and was "taking the appropriate actions". The representative went on to say that the Android security team rates the risk "moderate," as opposed to "high" or "critical" for many of the vulnerabilities it patches

Note, this is not the first Linux kernel vulnerability that has affected Android in the recent past, with Google in March admitting vulnerabilities in Android code based on Linux kernel versions 3.4, 3.10, and 3.14. The company had made available a patch to OEMs, and worked to remove the vulnerabilities from its own Nexus devices.

Advertisement

Last week, a set of vulnerabilities dubbed as QuadRooter surfaced and was claimed to affect roughly 900 million Android devices. According to researchers if any one of the vulnerabilities is exploited, an attacker can gain root access to the affected device.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple May Have Just Given Us a Sneak Peek at Its Foldable iPhone
  2. iOS 27 Release Date and How to Update: Supported iPhones
  3. Samsung Galaxy Watch 8 Gets More Secure With Latest Wear OS Patches
  4. Redmi Turbo 5 Battery, Camera Details Teased Ahead of Launch
  5. Vivo Y31s Launched in Malaysia With These Features
  6. Apple Unveils iOS 27 With Revamped Siri and Liquid Glass Improvements
  7. OnePlus Could Launch a New Budget Smartphone Lineup in India Soon
  8. iQOO Neo 12 Tipped to Offer Major Display Upgrade Over Predecessor
  9. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  1. Apple's First iOS 27 Beta Reportedly Contains Various Clues About Its Purported Foldable iPhone
  2. Honor X80 Pro Max in Development With Snapdragon 6 Gen 5 SoC and 11,000mAh Battery, Tipster Claims
  3. Redmi Turbo 5 India Variant to Feature Slightly Smaller Battery Than Chinese Version
  4. WWDC 2026: Apple Announces Custom EQ Feature for AirPods With iOS 27 Update
  5. Samsung Galaxy Watch 8, Watch 7 Get May 2026 Wear OS Update With Security Fixes
  6. Bitcoin Holds Above $63,400 as Institutional Buying Counters ETF Outflow Pressure
  7. Gears of War: E-Day, Clockwork Revolution Not 'One-Off', More Xbox Exclusives on Their Way
  8. WWDC 2026: Apple Showcases New Developer Tools for Improved App Store Discovery and Marketing
  9. Apple's iOS 27 Update to Arrive With Major Performance Upgrades for iPhone Including Faster AirDrop, App Launches and Search
  10. WWDC 2026: Apple Brings Visual Intelligence to Siri, Lets Users Access AI Information via iPhone Camera
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.