Breaking News

ASUS ROG Unveils Rapture GT-BE19000AI, the World’s First AI Gaming Router TerraMaster Unveils TOS 7 Insider Preview CORSAIR Steps Into the Ring, Announces Novablade Pro Wireless Hall Effect Leverless Fight Controller PROGRADE DIGITAL ANNOUNCES PG25 PRO THUNDERBOLT 5 DOCK Samsung TVs get HDR10 Plus Supported Content

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

MP3 Files Hack Billion Of Android Phones, Researchers Say

MP3 Files Hack Billion Of Android Phones, Researchers Say

Smartphones Oct 1,2015 0

zLabs VP of Research Joshua J. Drake has discovered yet another security issue on ther Android OS, which could allow attacks on more than one billion Android devices by hiding exploit code in MP3 and MP4 files. The same researchers had discovered scores of vulnerabilities in the Stagefright media playback tool in August . Going over the Stagefright code one more time, Drake and Zuk Avraham found further issues, dubbing them "Stagefright 2".

Stagefright 2.0 is a set of two vulnerabilities that manifest when processing specially crafted MP3 audio or MP4 video files. The first vulnerability (in libutils) impacts almost every Android device since version 1.0 released in 2008. The researchers found methods to trigger that vulnerability in devices running version 5.0 and up using the second vulnerability (in libstagefright). Google assigned CVE-2015-6602 to vulnerability in libutils.

The issue could allow remote code execution (RCE) via libstagefright on Android 5.0 and later. Older devices may be also impacted if the vulnerable function in libutils is used (using third party apps, vendor or carrier functionality pre-loaded to the phone).

The vulnerability lies in the processing of metadata within the files, so merely previewing the song or video would trigger the issue. Since the primary attack vector of MMS has been removed in newer versions of Google’s Hangouts and Messenger apps, the likely attack vector would be via the Web browser.

An attacker would try to convince an unsuspecting user to visit a URL pointing at an attacker controlled Web site (e.g., mobile spear-phishing or malicious ad campaign). An attacker on the same network could also inject the exploit using common traffic interception techniques (MITM) to unencrypted network traffic destined for the browser. 3rd party apps (Media Players, Instant Messengers, etc.) could also trigger an attack if they usethe vulnerable library.

Zimperium's team has notified the Android Security Team of this issue on August 15th. They assigned CVE-2015-6602 to the libutils issue but have yet to provide us with a CVE number to track the second issue.

Tags: android
Previous Post
Samsung Rejects Press Claim On TV Compliance Testing
Next Post
JDI Develops First Standard Monitor Size 17.3-inch 8K4K LCD Module

Related Posts

  • What’s new in Android 15, plus more updates

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • Android Gets a New Keyboard for Typing Braille

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

Latest News

ASUS ROG Unveils Rapture GT-BE19000AI, the World’s First AI Gaming Router
Enterprise & IT

ASUS ROG Unveils Rapture GT-BE19000AI, the World’s First AI Gaming Router

TerraMaster Unveils TOS 7 Insider Preview
Enterprise & IT

TerraMaster Unveils TOS 7 Insider Preview

CORSAIR Steps Into the Ring, Announces Novablade Pro Wireless Hall Effect Leverless Fight Controller
Gaming

CORSAIR Steps Into the Ring, Announces Novablade Pro Wireless Hall Effect Leverless Fight Controller

PROGRADE DIGITAL ANNOUNCES PG25 PRO THUNDERBOLT 5 DOCK
Cameras

PROGRADE DIGITAL ANNOUNCES PG25 PRO THUNDERBOLT 5 DOCK

Samsung TVs get HDR10 Plus Supported Content
Consumer Electronics

Samsung TVs get HDR10 Plus Supported Content

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed