Silent Circle, maker of the super-secure, privacy-focused Blackphone, has just patched its 1.x model of the phone from a security flaw that could have allowed a skilled attacker to compromise the phone.
The vulnerability (CVE-2015-6841) was discovered by security researchers at SentinelOne during a training session and was present in the Icera modem, which is included in the Blackphone 1 smartphones.
The researchers found that the modem left a socket open for connections, and that this socket was tied to an internal Android daemon with elevated privileges.
Attackers could have exploited this open port by sending commands to the modem, which would then connect them to the daemon in question and the Android system itself . In theory, this vulnerability would allow attackers to execute shell commands on the targeted Blackphone or, with the help of a specially crafted application, send more complex instructions. These had the ability to prevent the phone from ringing on calls, enable or disable caller ID on outgoing calls, send or receive invisible SMS messages to/from the device, factory reset some phone settings, silently forward incoming calls, make (visible) calls to other numbers, control which cell tower the phone connects to, make group calls, and various other functions that the researchers were unable to examine. SentinelOne reported the issue to Silent Circle in August through the company's bug bounty program and was awarded $500 (€460) for its efforts. Silent Circle fixed the issue in PrivatOS 1.1.13 RC3, the version of the company's Android operating system used in its Blackphone models .

In a Q&A on its blog, Silent Circle also clarified some of the scenarios in which this bug would have put its users at risk. Essentially, the vulnerability discovered by SentinelOne requires that the device had been infected at a previous stage, meaning that malware that could have taken advantage of this open port would have had to have been installed on the device beforehand.
The company's Blackphone 2.x branch of the secure phone is not affected by this issue.
