HomeSecurityVulnerability in Android 4.3 allows apps to bypass the lock screen...

Vulnerability in Android 4.3 allows apps to bypass device lock

android-trojan

In September, Google added remote device locking to Android management, allowing users to lock their phone if it’s stolen or lost. The mechanism allows the user to bypass the device’s existing locking system and set a random system password for better security. But recently, Curesec, a research team from Germany, has discovered an interesting vulnerability (CVE-2013-6271) in Android 4.3 that allows a rogue app to remove all existing device locks that have been activated by its owner.

"There is a bug in the 'com.android.settings.ChooseLockGeneric class.' This class is used to allow the user to modify the type of mechanism lock the device should have," the CRT team said in a blog post.

The Android OS has many mechanisms for locking and unlocking the device such as PIN, Password, gesture, and even facial recognition, although more than half of users do not use them. However, for each modification to the password settings, the device asks the user to confirm the previous lock.

But if a malicious application is installed on the device, it could exploit the flaw to unlock the device without knowing the previous passcode. Attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS