Black Hat 2015: Researchers discovered a vulnerability in Android devices that allows hackers to access a device remotely without the owner ever knowing. The flaw affects roughly 95% of Android devices running OS versions from 2.2 to 5.1, according to security firm Zimperium.
The error is due to a media library (used for processing media files) called Stagefright.
Zimperium reports that many vulnerabilities were found in this framework. The company plans to present its research at the Black Hat 2015 conference scheduled for August.
Using a person’s phone number, hackers can send a media file via MMS that allows them to gain entry into a device. The truly concerning thing, however, is that the device’s owner will never find out.
Hackers could theoretically send a trojan file while the device’s owner is sleeping, and gain access to his phone. They can then delete any evidence that shows the phone was compromised.
Once the exploit is completed, the hacker can remotely use a phone's microphone, steal files, read email messages, and intercept all personal credentials.
“These vulnerabilities are extremely dangerous because they do not require the victim to take any action to be exploited. Unlike spear-phishing, where the victim must open a PDF file or a link that has been sent by the attacker, this vulnerability can be triggered while the victim is asleep. Before waking up, the attacker will remove all indications that the device was compromised and will continue to have access to the trojaned phone”, says the technology head of Zimperium, Zuk Avraham.
Naturally, after this Google will have to promptly update all Android releases, which is extremely difficult.
