The makers of the BlackPhone – a mobile phone on the market that offers unusually high levels of security – have fixed a critical vulnerability that allows hackers to execute malicious code on mobile phones.
Attackers only need a phone number to send a message that can compromise devices through the Silent Text app.
The flaw could have dire consequences for the BlackPhone as the device is advertised for its security, and comes with a price tag that does not justify bugs.
"Successful exploitation could grant remote code execution privileges to the Silent Text app, which acts like a regular Android, but with some additional system privileges required to send and receive SMS. This gives the app access to contacts, location information, disk writes, and of course network access," Dowd said, noting that it took him about a week to discover the flaw.
The flaw could also be combined with other exploits to gain complete control of the device.
Source: secnews.gr

