Two researchers from Check Point's mobile security division have uncovered two vulnerabilities in LG's custom modification of the Android OS, which allows attackers to take control of the device.
The researchers presented their findings at this year's LayerOne security conference, but not before working with LG to address the issues.
Despite Google's efforts to secure the Android OS, changes made to the operating system by various OEMs have introduced new vulnerabilities exclusively to those devices. In this case, these two vulnerabilities affect one in five mobile devices in the US, according to a recent comScore survey.
The first issue they uncovered is a privilege escalation in an Android LG service called LGATCMDService. The researchers discovered that a malicious app could connect to this service, regardless of its initial access privileges, and gain “atd” user privileges.
An attacker could read or even write new IMEI and MAC, disable the USB connection, reboot the smartphone at will, erase the mobile phone's memory, or even render the device unusable completely.
"A ransomware would find these features very useful by locking a user out of a device and then disabling the ability to recover files when they connect the device to a computer via USB," the researchers say.
The second issue that the researchers helped LG fix is as dangerous as the first and can be found in the WAP Push protocol used to send URLs to mobile devices via the SMS protocol.
The two FireEye researchers claim that an SQL injection into the protocol components can be used to allow hackers to control the links sent to the user's devices.
The attacker can send the URLs in unread SMS messages and distribute links to malicious applications or phishing pages to steal credentials.

