HomeSecurityBug affects LG Android smartphones from the last seven years!

Bug affects LG Android smartphones from the last seven years!

LG last month released a security update to fix a bug that affects Android smartphones sold in the last seven years. The vulnerability, identified as CVE-2020-12753, affects the bootloader that ships with LG smartphones. Separate from the Android operating system, the bootloader is a piece of firmware that is specific to each smartphone vendor. It is the first piece of code that runs when a user boots up their device and ensures that the smartphone firmware and the operating system boot properly and securely.

In March, Max Thomas, a software engineer in the US, discovered a vulnerability in the bootloader component that was added to LG smartphones starting with the LG Nexus 5. In a technical analysis of the vulnerability published on Tuesday, Thomas notes that the bootloader component’s graphics package contains a bug that allows attackers to hide their own code to run alongside the bootloader graphics under certain conditions, such as when the battery is low and when the device is in the bootloader’s Download Mode. Thomas adds that attackers can gain the ability to run their own custom code, which would allow them to take control of the bootloader and, by extension, the entire device. The bug affects all LG smartphones using QSEE (Qualcomm Secure Execution Environment) chips running the EL1 or EL3 firmware, and all devices running Android 7.2 and later.

Bug affects LG Android smartphones from the last seven years!

The vulnerability, identified as CVE-2020-12753, is what researchers call a “Cold Boot Attack,” meaning a vulnerability that can only be exploited by physically accessing and logging into a vulnerable device. However, that doesn’t mean the bug affects devices any less. In the event that a user’s device is stolen or confiscated, this vulnerability can be used to give the new owner control of the device and “unlock its secrets.”.


LG released a patch for this bug in security update LVE-SMP-200006, which the company released in early May 2020. Device owners who have a device model that is at risk every day should apply the LVE-SMP-200006 update. Thomas also released a proof-of-concept code, which he used to “crack” the bootloader on an LG Stylo 4 smartphone.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS