Security researchers at Trend Micro have identified a dangerous bug in Debuggerd, the debugger built into the Android, which could be combined with other security vulnerabilities to achieve arbitrary code execution on the device.
The vulnerability is found in all versions of Android, starting from version 4.0 (Ice Cream Sandwich) up to version 5.x (Lollipop) – which currently represent 94.1% of mobile devices.
[alert variation=”alert-info”]According to research, the majority of Android users, at 39.2%, have version 4.4 of the operating system (commonly known as KitKat), while 37.4% of users have a device with Android 4.1 (Jelly Bean). Lollipop, the latest version of the operating system, represents only 12.4% of the Android market.[/alert]
Trend Micro researchers discovered that an attacker could create a special ELF (Executable and Linkable Format) executable file to crash the debugger, gaining access to data logs stored in memory.
This vulnerability cannot be used by itself to execute arbitrary code, but the information it provides access to can be exploited to bypass Address Space Layout Randomization (ASLR) protection mechanisms. Once this is achieved, specially crafted malicious code can run on the device.
The bug can be exploited for denial-of-service purposes, repeatedly leading to crashes of the built-in debugger.
“This vulnerability could be exploited by a malicious or repackaged application downloaded to the device, although the impact would be relatively limited,” Trend Micro researcher Wish Wu said in a blog post, stressing that exploiting the vulnerability could not lead to malicious code execution.
Trend Micro disclosed the vulnerability to Google on April 27, which was rated as low critical. There is currently no patch available for the affected versions of Android, but a patched version of the vulnerable code is included in the next version of the operating system (Android M), which is expected to be released in October/November.

