HomeSecurityWhat is the RAMPAGE Attack that can affect any Android from...

What is the RAMPAGE Attack that can affect any Android since 2012?

RAMPAGEA team of eight researchers created an exploit called RAMPAGE (CVE-2018-9442), which allows unauthorized access to Android.

What is a RAMPAGE attack?

In 2012, with the release of Android ICS, Google introduced a new component in the Android kernel called ION that allocates memory for different applications and services. RAMPAGE targets ION, thus becoming a threat to millions of Android devices around the world.

However, we shouldn't blame Android for everything. The attack can be carried out due to a RAM hardware flaw called Rowhammer that occurs on ARM-based devices. In modern RAM chips, memory cells are packed very close together. This could result in them leaking their charge and interacting with each other.

Each memory cell contains a memory bit that represents a unit of data on the RAM chip. The attack can be used to extract data from the RAM chip by changing the state of a memory bit from 0 to 1 and vice versa.

How does RAMPAGE work?

A malicious application equipped with RAMPAGE can use the ION memory subsystem and cause a row of memory bits to change their state repeatedly, until a bit flip occurs in the adjacent row.

This way, an app could potentially gain administrator privileges to access data from another app. It could collect confidential information such as passwords, documents, photos, messages, etc.

 How do I know if my device has been affected?

As mentioned above, all Android 4.0 and above devices released since 2012 and using LPDDR2, LPDDR3 or LPDDR4 RAM chips could be affected. However, it is not confirmed that the attack could be carried out on iOS, Windows, MacOS, or cloud servers.

The story isn't as scary as it sounds, though. Modern operating systems don't write all the information about an application to adjacent memory cells. It's spread across different cells. The process of flipping bits may be easier, but finding out what's written in the memory bits isn't. An average Android smartphone with 32GB of memory has 32 billion bits. Given this fact, it would be nearly impossible for an attacker to track down a specific piece of information.

What should I do?

First of all, don't worry. Google and Amazon have already been notified of RAMPAGE, so it's less likely that a malicious app will appear on Google Play, and if there is ever a problem, the companies will certainly create patches. Furthermore, it's not known whether the vulnerability exists in the real world.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS