HomeSecurityBe quiet! Your Android device is monitoring your calls

Be quiet! Your Android device is monitoring your calls

Just because you don't give an app access to your microphone doesn't mean it can't listen to you. Researchers have created an attack called Spearphone that uses the motion sensors in Android phones to listen in on phone calls, interactions with your voice assistant, and more.

Android

When you install an Android app, it asks for your permission to access your microphone so it can hear what you say. However, researchers have discovered a workaround.

Most modern smartphones have accelerometers that supposedly sense how fast you're moving, which are useful for things like fitness apps. Android apps don't need permission to use the phone's accelerometer, so the researchers used it as a listening device. The smartphone's speaker causes the device to vibrate, so the researchers were able to hijack the accelerometer to test those vibrations.

The attack used a combination of signal processing and machine learning to convert vibration samples into speech. The technique works whether the phone is on a table or held in the user's hand, as long as the phone is outputting sounds through the speaker and not through the earpiece.

As the researchers claimed, they could determine the gender and identity of the remote speaker with a probability of 90% and 80% respectively, with as little as a single word.

The researchers' paper lists several possible attacks. The software could eavesdrop on a phone call, detecting the gender and possibly the identity of the remote person. It could also use speech recognition to understand what they are saying.

The software could also use the technique to listen to “audio files,” he warned, pointing to a sneaky commercial application:

Advertising companies could use this information to target victims with customized ads, according to the victim's preferences.

Finally, motion sensors could listen to your digital voice assistant to learn exactly what you asked it, for example where to meet on a date.

An attacker would have to plant some malware on the phone, but given that many fake apps already do illegal things on users' phones, this is not very unlikely. Alternatively, the attack code could run in JavaScript if the user was on a malicious website at the time.

The most obvious protection measure is to enable permissions controls for the accelerometer, as Google has done for other sensors like GPS. However, this would directly impact the usability of smartphones, the researchers argued, and in any case, users don't always heed the permissions notices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS