Millions of Android Devices Vulnerable to Hardware Based Attack That Gives Root Access

Advertisement
By Tasneem Akolawala | Updated: 24 October 2016 18:30 IST
Highlights
  • The Drammer attack exploits hardware components to access data
  • Researchers in Amsterdam demoed this vulnerability
  • They could completely root Samsung and OnePlus smartphones

Researchers of VUSec Lab at Vrije Universiteit Amsterdam have discovered a new way in which hackers can take control of millions of Android devices. In their demo, they showed how hackers could exploit data on smartphones through memory chips and other physical parts embedded inside, opening up a whole new world of vulnerabilities that wasn't thought of before. In theory, the type of attack - which exploits a new-found flaw in mobile memory - could be users on iPhones as well as other mobile devices.

The Drammer exploit is based on the Rowhammer class of attacks that target memory chips like DRAM, and has the potential to root millions of Android smartphones out there, including the ones that are running on ARM chips. This new exploit leverages a memory hardware vulnerability to surreptitiously root gain access using an app without any special permissions. The researchers claim that they have used the Drammer attack to root many LG, Motorola, Samsung, and OnePlus handsets.

Ars Technica reports that the researchers have been able to completely root Nexus 4, Nexus 5, LG G4; Moto G (2013), Moto G (2014), Samsung Galaxy S4, Samsung Galaxy S5, and the OnePlus One using the Drammer attack.

Advertisement

What is worse is that there is no quick fix for this exploit as well. Hardware bugs weren't even considered a possibility, and therefore no software fix was ever issued for them. "Until recently, we never even thought about hardware bugs [and] software was never written to deal with them. Now, we are using them to break your phone or tablet in a fully reliable way and without relying on any software vulnerability or esoteric feature. And there is no quick software update to patch the problem and go back to business as usual," one of the researchers, Victor van der Veen told the publication.

Advertisement

However, the report further notes that not all units of the above-mentioned smartphones were compromised. It largely depended on the age of the smartphone, and older the smartphone, the more vulnerable was it to the exploit - this is based on how the vulnerability works, by flipping bits on a memory module. The Rowhammer attack has been around for quite a while, but this is the first time it is seen risking smartphone data.

The researchers had even intimated Google about the vulnerability in July, for which they even received a $4,000 reward. Google is still working on a fix, and plans to release it in the November security bulletin.

Advertisement

Veen claims that the fix won't completely prevent hackers from exploiting, but expects it to make it very difficult. You cannot expect an OEM to stop bundling in random access memory chips and other crucial hardware components to prevent the Rowhammer exploit.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Unveils Signature Phone With Four 50-Megapixel Cameras
  2. Redmi Pad 2 Pro 5G With 12,000mAh Battery Arrives in India: See Price
  3. Motorola Unveils Razr Fold as its First Book-Style Foldable at CES
  4. Realme 16 Pro Series With 7,000mAh Battery Debuts in India: See Price
  5. Redmi Note 15 5G First Impressions
  6. CES 2026: Motorola Enters the Wearable AI Race With Project Maxwell
  7. iQOO Z11 Key Specifications Confirmed Ahead of Imminent Launch in China
  8. Vivo Y50s 5G, Vivo Y50e 5G Launched With 6,000mAh Battery: Price, Features
  9. Vivo X200T Said to Launch in India With 'Aggressive' Pricing
  10. Realme 16 Pro+, Realme 16 Pro Review: A New Dawn for Realme
  1. OnePlus Turbo 6 Series Confirmed to Feature BOE Displays With Up to 165Hz Refresh Rate
  2. Lenovo Legion Go 2 SteamOS Version Revealed at CES 2026, Will Be Available From June 2026
  3. Motorola Unveils Unified AI Platform and AI Pin-Styled Wearable Device Prototype at CES 2026
  4. iQOO Z11 Turbo Battery, Charging Details Confirmed; Tipster Leaks Camera Specifications
  5. CES 2026: Eureka Z50, E10 Evo Plus Robot Vacuum Cleaners Launched, FloorShine 890 Tags Along
  6. Motorola Unveils Signature Phone With Snapdragon 8 Gen 5 Chip and 50-Megapixel Sony LYTIA Cameras: Price, Specifications
  7. CES 2026: Motorola Razr Fold Announced With 2K LTPO Inner Display, 50-Megapixel Triple Cameras
  8. Self-Driving Cars Could Prevent Over 1 Million Road Injuries Across the U.S. by 2035
  9. Astronomers Measure Mass and Distance of a Rogue Planet for the First Time in History
  10. The Rip OTT Release Date: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.