HomeSecurityOne billion Android users are exposed to SMS phishing attacks

One billion Android users are exposed to SMS phishing attacks

Android According to Check Point Research, some Android phones, including phones from Samsung, Huawei, LG and Sony, have been found to have a security vulnerabilitythat allows phishing attacks to be carried out.

The Android phones affected by this vulnerability use over-the-air (OTA) provisioning, in which mobile network operators make special settings for a new phone that connects to their network . However, researchers found that the industry standard for OTA provisioning, Open Mobile Alliance Client Provisioning (OMA CP), lacks adequate authentication procedures. If hackers exploit this vulnerability, they could impersonate network administrators and send deceptive OMA CP messages to Android device users

Below you see a deceptive CP message to a Samsung phone user.

One billion Android users are exposed to SMS phishing attacks

The message urges users to accept settings that are actually malicious and can route all data flow through a proxy server (owned by the attacker). If this is done, the attacker will be able to access data and read the emails of Android users.

Samsung phones are the most vulnerable

According to the researchers, some Samsung phones are more vulnerable to this form of attackbecause they do not verify the authenticity of the senders of OMA CP messages . If the user accepts the CP, then the malware will be installed , without the need for proof of the sender's identity.

One of the researchers said that this security issue needs to be addressed immediately. It is a critical vulnerability, as it affects a huge number of devices. Android devices are among the most widespread.

“If there is not a stronger form of authentication, a malicious hacker can easily carry out a phishing attack via over-the-air provisioning. When the user receives an OMA CP message, they have no way to distinguish if it comes from a trusted source. By clicking the “Accept” button, the user could give an intruder access to their phone».

Phones from Huawei, LG, and Sony have a form of authentication, but if hackers find the recipient's International Mobile Subscriber Identity (IMSI), they are able to "verify" their identity and gain access to the phone.

The hackers can easily find a user's IMSI. They can use a malicious Android app that reads the IMSI of a phone as soon as it is installed. However, there is also a way to bypass the IMSI step by sending the user a message that is supposed to come from the network administrator and ask them to accept an OMA CP message. If the user enters the PIN number and accepts the OMA CP message, the CP can be installed without IMSI.

Researchers have been notifying companiesaffected by the vulnerability since March 2019.

Corrections

Samsung included a fix for the vulnerability in the May update (SVE-2019-14073)

Huawei plans to fix the issue in the next generation of smartphones of the Mate or P series

LG fixed the issue in July (LVE-SMP-190006)

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS