HomeSecurityOnePlus devices receive GPS data from insecure servers

OnePlus devices receive GPS data from insecure servers

 

servers

According to a new report by Piunikaweb, some OnePlus smartphones are downloading GPS data via insecure HTTP servers.

It is rumored that OnePlus engineers were able to override the standard AOSP (Android Open Source Project) policies and install the debug build of gps.conf on OnePlus' OxygenOS operating system.

This led to the activation of insecure XTRA servers by a Chinese OnePlus engineer.

The XTRA servers contributed to the capture of GPS, GLO and BDS data and allowed any potential malicious attacker to change the location data on a user's GPS, which can be used to trick users into following a different and incorrect route.

The report suggests that a member of the LineageOS company helped verify the problem of receiving data through unsecured servers.

After this, Piunikaweb filed a bug report on the OnePlus forum and a moderator from the company, named Funk Wizard, responded saying that the issue would be fixed soon.

He stated: “To receive data from XTRA servers, the device reads the address in the Configure of the Modem NV, which passes over HTTPS instead of HTTP and the GPS.conf is already ignored so that the XTRA config does not work. Thanks for the update and we will synchronize GPS.conf with HTTPS in the upcoming updates to fix the problem.”

However, it is suggested that the issue still exists and there is no update on whether or not OnePlus installed the debug on purpose.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS