HomeSecurityCode that exploits critical Stagefright bug in Android exposed

Code that exploits critical Stagefright bug in Android exposed

Stagefright bugsStagefright bugs: Code that allows hackers to take control of vulnerable Android devices has been published recently, while developers and Google are still trying to find a way to distribute patches to thousands of users.
The vulnerability at the heart of Android, located in the Android media library, known as libstagefright , gives attackers a variety of ways to secretly execute malicious code on unsuspecting users' devices.
The vulnerabilities were reported privately in April and May and publicly disclosed in late July. Google has spent the past four months preparing fixes and distributing them to its partners, but those efforts have faced a number of obstacles and limitations.
The hurdles forced Google and its partners to ask Zimperium — the security firm that uncovered the Stagefright bugs — to delay publishing proof-of-concept code that exploits some of the bugs. But on Wednesday, the company finally released it. The python script creates an MP4 media file that exploits CVE-2015-1538 and provides an attacker with a reverse command cell. The attacker is then able to take photos and listen to audio remotely. The exploit doesn’t work in versions 5.0 and later thanks to new overflow mitigations.
The company responded to all the negative publicity it received over the Stagefright bugs by pledging to follow a monthly cycle for Nexus handsets. Samsung announced a patch program for many of its devices. If you're wondering how the new programs will work, with any luck they will allow Google to keep up with the industry-standard patch cycles followed by Microsoft, Apple, and Adobe.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS