QuadRooter Android Security Bugs Affect over 900 Million Devices

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
A set of four vulnerabilities in Qualcomm chipsets allow an attacker to gain root-level access on Android devices, which, according to the latest statistics, translates to over 900 million affected tablets and smartphones.

quadrooter-android-security-bugs-affect-over-900-million-devices-507052-3.png



The four vulnerabilities have been disclosed today at the DEF CON 24 security conference in Las Vegas by a team of Check Point researchers.

The four security flaws are CVE-2016-2503 (found in Qualcomm's GPU driver, fixed in Google's Android Security Bulletin for July 2016), CVE-2016-2504 (Qualcomm GPU driver, fixed in Google's Android Security Bulletin for August 2016), CVE-2016-2059 (Qualcomm kernel module, fixed in April, patch status unknown), and CVE-2016-5340 (Qualcomm GPU driver, fixed, patch status unknown).

Simple exploitation routine
All four flaws can be exploited just by installing a rogue app on your device. To carry out the exploitation routine, the attacker's app does not need any special permissions, making it more likely that users would install the app without thinking anything malicious might be hiding inside.

Any of the four flaws will allow an attacker to escalate the app's permissions from user-level to root-level, granting them full access to any phone features.

This means an attacker can download and install malware and malicious apps without any interaction from the user, all done in the phone's background.


Read more: QuadRooter Android Security Bugs Affect over 900 Million Devices
 

DardiM

Level 26
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
May 14, 2016
1,597
Thanks for the share :)

The fact it doesn't need any special permissions make it very dangerous.
A lot of people doesn't trust apps when they see the (long) list of permissions they must allow, me first :oops:

"The four vulnerabilities have been disclosed today at the DEF CON 24 security conference in Las Vegas by a team of Check Point researchers."

I wonder how many users have been infected by apps using this vulnerabilities :rolleyes:
 
Last edited:

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
That is the advantage of using Apple products, since updates came focus on their own, so impact of vulnerabilities is minimal.

However the logic of open-source should help to improve and lessen the possible risk; but because of being open hence the area of attacks widen.
 
  • Like
Reactions: Logethica

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top