Sensors: Malicious applications can now access sensor data present in modern smartphones and collect sensitive data and other phone information which, if exploited properly, can guess the device's PIN
That's the conclusion of research published this month by researchers at Nanyang Technological University (NTU) in Singapore. The three scientists behind it noticed a security flaw in the design of Android and iOS mobile operating systems. The researchers say that these operating systems do not require apps to give the user permission to access sensor data.
In order to see it in practice, they created an Android that they installed on test devices and collects data from six sensors: Accelerometer, Gyroscope, Magnetometer, Proximity Sensor, Barometer, and Ambient Light Sensor. The application's algorithm mainly collects the taps that the screen receives and at what point. By collecting all this data, they were able to "guess" the PIN on 99% of the devices that had the 50 most common PIN codes for smartphone devices. This percentage dropped to 82% when the test was carried out for 10,000 devices with a four-digit PIN and with a total of 20 attempts for each mobile.
The real problem, however, as pointed out by the NTU team, is the ability of apps to access sensor data without always asking for permission from users. Both Android and iOS are affected by this issue. Therefore, Google and Apple respectively will have to fix the issue.

