Breaking News

Microsoft Announces Security Copilot AI Nintendo Announces Switch OLED - The Legend of Zelda: Tears of the Kingdom Edition The Spring Sale comes to PlayStation Store QNAP Releases QTS 5.1.0 Beta ASUS Announces April Availability of new ProArt Displays

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

MP3 Files Hack Billion Of Android Phones, Researchers Say

MP3 Files Hack Billion Of Android Phones, Researchers Say

Smartphones Oct 1,2015 0

zLabs VP of Research Joshua J. Drake has discovered yet another security issue on ther Android OS, which could allow attacks on more than one billion Android devices by hiding exploit code in MP3 and MP4 files. The same researchers had discovered scores of vulnerabilities in the Stagefright media playback tool in August . Going over the Stagefright code one more time, Drake and Zuk Avraham found further issues, dubbing them "Stagefright 2".

Stagefright 2.0 is a set of two vulnerabilities that manifest when processing specially crafted MP3 audio or MP4 video files. The first vulnerability (in libutils) impacts almost every Android device since version 1.0 released in 2008. The researchers found methods to trigger that vulnerability in devices running version 5.0 and up using the second vulnerability (in libstagefright). Google assigned CVE-2015-6602 to vulnerability in libutils.

The issue could allow remote code execution (RCE) via libstagefright on Android 5.0 and later. Older devices may be also impacted if the vulnerable function in libutils is used (using third party apps, vendor or carrier functionality pre-loaded to the phone).

The vulnerability lies in the processing of metadata within the files, so merely previewing the song or video would trigger the issue. Since the primary attack vector of MMS has been removed in newer versions of Google’s Hangouts and Messenger apps, the likely attack vector would be via the Web browser.

An attacker would try to convince an unsuspecting user to visit a URL pointing at an attacker controlled Web site (e.g., mobile spear-phishing or malicious ad campaign). An attacker on the same network could also inject the exploit using common traffic interception techniques (MITM) to unencrypted network traffic destined for the browser. 3rd party apps (Media Players, Instant Messengers, etc.) could also trigger an attack if they usethe vulnerable library.

Zimperium's team has notified the Android Security Team of this issue on August 15th. They assigned CVE-2015-6602 to the libutils issue but have yet to provide us with a CVE number to track the second issue.

Tags: android
Previous Post
Samsung Rejects Press Claim On TV Compliance Testing
Next Post
JDI Develops First Standard Monitor Size 17.3-inch 8K4K LCD Module

Related Posts

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • Android Gets a New Keyboard for Typing Braille

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

  • Google Explains Why New Huawei Smartphones Don't Come With Google Play Apps

Latest News

Microsoft Announces Security Copilot AI
Enterprise & IT

Microsoft Announces Security Copilot AI

Nintendo Announces Switch OLED - The Legend of Zelda: Tears of the Kingdom Edition
Gaming

Nintendo Announces Switch OLED - The Legend of Zelda: Tears of the Kingdom Edition

The Spring Sale comes to PlayStation Store
Gaming

The Spring Sale comes to PlayStation Store

QNAP Releases QTS 5.1.0 Beta
Enterprise & IT

QNAP Releases QTS 5.1.0 Beta

ASUS Announces April Availability of new ProArt Displays
Cameras

ASUS Announces April Availability of new ProArt Displays

Popular Reviews

Withings Thermo Wi-Fi-connected temporal thermometer

Withings Thermo Wi-Fi-connected temporal thermometer

Withings Body Plus Scale

Withings Body Plus Scale

Withings Sleep Analyzer

Withings Sleep Analyzer

EnGenius ECW230 Access Point

EnGenius ECW230 Access Point

Pioneer BDR-S13U-X Blu-Ray Recorder

Pioneer BDR-S13U-X Blu-Ray Recorder

EnGenius ECW230S AP

EnGenius ECW230S AP

Noctua NH-D12L CPU Cooler

Noctua NH-D12L CPU Cooler

be quiet! Pure Rock 2 FX

be quiet! Pure Rock 2 FX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed