A Chinese researcher has discovered an exploit that allows hackers to break into Android devices through the Chrome browser.
Speaking at the PacSec conference held in Tokyo this month, security researcher Guang Gong of Qihoo 360 demonstrated the zero-day, managing to take full control of an updated Android device.
The Chinese researcher used a JavaScript V8 bug through the Chrome browser to gain control over a Google Project Fi Nexus 6 device running the latest version of the OS, namely Android 6.0 Marshmallow.
He then used a Java flaw to install an arbitrary application that helped him gain remote control over the device.
The attack has been dubbed a “one-shot exploit” because it can essentially do everything in one go. The hack is very serious, as it puts millions of Android devices at risk, since they all use JavaScript.
