Rowhammer-Based 'GLitch' Exploit Emerges That Can Attack Android Devices via Browsers

Advertisement
By Jagmeet Singh | Updated: 4 May 2018 18:53 IST
Highlights
  • Researchers have developed an exploit based on Rowhammer technique
  • The exploit puts some Android devices at risk
  • It uses GPU to gain backdoor access

A team of researchers has discovered a new way that lets attackers hit Android devices remotely by leveraging a four-year-old technique called Rowhammer. Called GLitch, the fresh exploit uses GPU to gain backdoor access on some Android smartphones and can be executed simply through a malicious website. It was in 2016 spotted that a Rowhammer-based exploit could root Android devices and leak their stored data. However, that previous exploit required attackers to install a malicious app on vulnerable hardware to obtain user data.

Researchers of VUSec Lab at Vrije Universiteit Amsterdam have elaborated the GLitch exploit in a paper and claimed that it takes about two minutes to attack a vulnerable Android device by pushing code from a JavaScript component available on a malicious site. The exploit notably uses standard JavaScript to compromise the device, instead of requiring any app installation or a special Web program. It essentially accesses GPU through a Rowhammer-vulnerable DRAM to take over the system. This is unlike the previous Rowhammer attacks that were majorly using CPU to exploit a system.

Thankfully, the scope of the GLitch exploit isn't as wide as the Drammer that emerged in October 2016 to attack millions of Android devices using a malicious app. The new exploit works only Mozilla's Firefox browser and can impact devices using Snapdragon 800 and Snapdragon 801 SoCs, which has the Adreno 330 GPU. Moreover, the researchers found their model successful on older devices such as the Nexus 5 that had been discontinued in the past.

Advertisement

In a statement to Ars Technica, Pietro Frigo, one of the four researchers in Vrije University Amsterdam Systems and Network Security Group who authored the paper, assured that on different browsers, attackers could require different techniques to build the exploit. "But, theoretically, you could exploit any target," he added.

Advertisement

That being said, Google in an official note to folks at Ars Technica stated that the remote vector in Chrome has been mitigated on March 13 and its team is working with other browsers to implement similar protections. Mozilla, on the other hand, disabled the vulnerable EXT_DISJOINT_TIMER_QUERY in the March release of Firefox 59 and is set to change the WebGL specifications in Firefox 60 that will be released on May 9 to make it harder for attackers to compromise devices through any Rowhammer-based exploits. Furthermore, Some anonymous Google researchers reportedly confirmed that newer Android phones come with DDR chips that have mitigations to protect the hardware from the GLitch exploit and prevent bits from flipping, which primarily gives space to Rowhammer attackers.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Rowhammer, GLitch, VUSec Lab, Android
Advertisement
Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Nothing Phone 3a Lite Goes on Sale in India at This Price
  4. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  5. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  6. Airtel Discontinues These Prepaid Recharge Packs in India
  7. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  8. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  9. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  10. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  4. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  5. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  6. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  7. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  8. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  9. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  10. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.