HomeSecurityCertifi-gate|The Android vulnerability that affects millions of devices

Certifi-gate|The Android vulnerability that affects millions of devices

A new Android vulnerability (Certifi-gate) has been discovered by security researchers at Check Point. The researchers disclosed the vulnerability at Black Hat USA 2015, and reported that it allows an attacker to gain complete (remote) control of a device using mobile Remote Support Tools (mRSTs).

Certifi-gate

These tools (mRSTs) were added to Android to allow IT to troubleshoot and resolve issues without the device owner having to go to a support center.

In short, they allow support staff to connect remotely, interact with the user's device, or even apply patches.

But because mRSTs have system-level privileges, it makes them an ideal target for hackers.

The Check Point analyzed the authentication methods used by mRSTs to authenticate a support application used by remote IT departments, and discovered that malicious actors could easily disguise themselves as valid support requests. This allowed them to successfully launch attacks that granted them system-level privileges on any device.

This allows hackers access to all the phone's functions, which means they can intercept phone calls, intercept messages, photos, install apps, and anything else you can think of.

According to Check Point, the Certifi-gate vulnerability has been found in the following support applications: AnySupport, CommuniTake, RSupport, and TeamViewer.

Below are two videos demonstrating the vulnerability.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS