Hanan Be’er, a security researcher for the Israeli company NorthBit, has developed a fully functional exploit that leverages the Stagefright vulnerability to put Android devices at risk.
Security researchers at Zimperium discovered the Stagefright vulnerability last August, forcing Google to begin providing monthly security updates for Nexus devices next month.
Google tried to fix Stagefright last September, but an incomplete solution and the discovery of the Stagefright 2.0 exploit made the problem worse and increased its bad reputation.
Now, more than half a year after Stagefright surfaced, NorthBit has released details about an exploit routine that can exploit the libstagefright library in the Android Mediaserver component to compromise devices as a whole.
The exploit was built on another piece of exploit code that was released both by Zimperium, the company that discovered the Stagefright vulnerability, and by Google.
The NorthBit attack scenario is quite simple. An attacker needs to trick a user into entering a website, where a malicious image or video is hosted.
Because the Stagefright flaw destroys Android devices when reading metadata from media files, the user must go to the attacker’s website to be exposed to the attack.
The good is that the attack takes some time to execute because it needs to go through three different stages. The bad is that mobile connections are inherently slow and most users will wait. Additionally, the attack can be carried out when the user is already watching another larger video.
During the first stage, a malicious image/video containing the exploit code forces the user's Mediaserver component to restart, which allows the attacker to gather information about each different user.
Using this data collected from the device, the attacker's server creates a custom video file for each victim, which is more powerful than the first payload and runs with root privileges, allowing the attacker to recover data from the device or install spyware or other malware (third stage).
This new exploit, called Metaphor, works on Android 2.2 through 4.0, and also on Android 5.0 through 5.1, even though these newer versions have ASLR (Address space layout randomization) protection. Ironically, to bypass ASLR protection, NorthBit uses the Stagefright exploit released by Google.
During their tests, the researchers exploited Metaphor against the Nexus 5, the HTC One, the LG G3 and the Samsung Galaxy S5. Below is a video of the attack in action:
[su_youtube url=”https://www.youtube.com/watch?v=I507kD0zG6k” width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]

