New Android Flaw, Gain Access via a Text Message

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
In this attack, the target would not need to goof up — open an attachment or download a file that's corrupt. The malicious code would take over instantly, the moment you receive a text message.

"This happens even before the sound that you've received a message has even occurred," says Joshua Drake, security researcher with Zimperium and co-author of Android Hacker's Handbook. "That's what makes it so dangerous. [It] could be absolutely silent. You may not even see anything."

Here's how the attack would work: The bad guy creates a short video, hides the malware inside it and texts it to your number. As soon as it's received by the phone, Drake says, "it does its initial processing, which triggers the vulnerability."

The messaging app Hangouts instantly processes videos, to keep them ready in the phone's gallery. That way the user doesn't have to waste time looking. But, Drake says, this setup invites the malware right in.

If you're using the phone's default messaging app, he explains, it's "a tiny bit less dangerous." You would have to view the text message before it processes the attachment. But, to be clear, "it does not require in either case for the targeted user to have to play back the media at all," Drake says.

Once the attackers get in, Drake says, they'd be able do anything — copy data, delete it, take over your microphone and camera to monitor your every word and move. "It's really up to their imagination what they do once they get in," he says.

[...]

NPR has asked leading phone makers and wireless service providers whether they'll fix the bug. We're waiting for responses and will post them to this page.
 

Kardo Kristal

From Crystal Security
Verified
Top Poster
Developer
Well-known
Jul 12, 2014
1,143
@Huracan Thanks for sharing this interesting news. :)

Regards,
Kardo
 
Last edited:

Korora

Level 2
Verified
Jul 22, 2015
58
This is quite shocking as I personally wouldn't think this would be able to happen, but it doesn't surprise me much.

Thanks for sharing @Huracan
 

Rolo

Level 18
Verified
Jun 14, 2015
857
I don't know why he lumped the Nexus with carrier-delayed devices since the Nexus runs straight Google Android and they are the first to get Google updates since there is no vendor delay. This is the main reason why I prefer the Nexus (I have a 5 myself).
 
  • Like
Reactions: jn2002dk

Enju

Level 9
Verified
Well-known
Jul 16, 2014
443
The mother of all Android bugs was found! :D
In only one text message you can wiretap almost every Android based smartphone and even delete your traces.
The best part is: Google has released a fix for it but most producers have yet to implement it.
 
Last edited:

souhrid

Level 5
Jun 29, 2012
226
I don't expect Samsung to fix any of their models except their newest ones... the others are a mixed bag.
This is one of the major drawback of Android OS, we depend on our phone manufacturers for upgrade and even for bug fixes. If this remain unsolved I surely believe that Android will fail against windows phones. Windows mobile will be the future.
 
  • Like
Reactions: Enju

Enju

Level 9
Verified
Well-known
Jul 16, 2014
443
This is one of the major drawback of Android OS, we depend on our phone manufacturers for upgrade and even for bug fixes. If this remain unsolved I surely believe that Android will fail against windows phones. Windows mobile will be the future.
I don't think most people really care about their security and privacy (Facebook is a great example here...), otherwise sheeple wouldn't use Facebook or buy Samsung (or almost any other Android smartphone producer).
 
  • Like
Reactions: Rolo and souhrid

souhrid

Level 5
Jun 29, 2012
226
I don't think most people really care about their security and privacy (Facebook is a great example here...), otherwise sheeple wouldn't use Facebook or buy Samsung (or almost any other Android smartphone producer).
Maybe we should switch to lumia
 
  • Like
Reactions: Enju

JakeXPMan

Level 17
Verified
Top Poster
Well-known
Oct 20, 2014
804
Just heard this on the morning news, it was said... no patch has been released as of yet.
 
  • Like
Reactions: Enju

Enju

Level 9
Verified
Well-known
Jul 16, 2014
443
Just heard this on the morning news, it was said... no patch has been released as of yet.
CyanogenMod and AOSP have already implemented the bugfixes in their nightlies, who knows how long it will take for the others... in the meantime you can disable MMS on your phone as a workaround. If you are using a HTC phone and got a update this month the bugs should be fixed too.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
That's nasty but still if you are not using Hangouts then that risk for possibility is low, typically call and text should be fine.

But of course there still a risk but its a matter of time if he/she trap on that scheme while using outdated Android.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top