HomeSecurityVulnerability in Qualcomm chips affects 40% of mobile phones

Qualcomm chip vulnerability affects 40% of mobile phones

A high-severity security vulnerability found in Qualcomm's Mobile Station Modem (MSM) chips (including the latest 5G-capable versions) could allow attackers to access text messages and call history. They could also eavesdrop on mobile users' conversations.

Qualcomm

See also: Is Qualcomm preparing a Nintendo Switch clone?

Qualcomm MSM is a series of 2G, 3G, 4G and 5G-capable systems on chips (SoCs) used in 40% of all mobile phones from multiple vendors, including Samsung, Google, LG, OnePlus and Xiaomi.

“If exploited, the vulnerability would allow an attacker to use the Android OS itself as an entry point to inject malicious code into phones,” said the Check Point researchers who discovered the vulnerability, CVE-2020-11292.

Also, the security flaw could allow attackers to unlock the subscriber identity module (SIM) used by mobile devices to securely store network authentication information and contact details.

See also: Qualcomm is building a competitor to Apple's M1 chip

To exploit CVE-2020-11292 and take control of the modem and patch it dynamically from the application processor, attackers must abuse a heap overflow vulnerability in the Qualcomm MSM Interface (QMI) used by the company's cellular processors to interface with the software stack.

Malicious apps could use the vulnerability to hide their activity under the modem chip itself, rendering the security features that Android uses to detect malicious activity.

Check Point disclosed its findings to Qualcomm in October, which subsequently confirmed the company's findings, rated the vulnerability as high severity, and notified relevant suppliers.

See also: Qualcomm acquired NUVIA, faster processors are coming!

To protect themselves from malware exploiting this or other similar security flaws, Check Point advises users to update their devices to the latest operating system versions that typically come with security updates.

Additionally, installing apps from official app stores will significantly minimize the risk of accidentally installing malicious apps.

More technical details about the CVE-2020-11292 vulnerability are available in the report published today by Check Point.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS