HomeSecurityAndroid 5.x Lockscreens are bypassed with long random passwords

Android 5.x Lockscreens are bypassed with long random passwords

There is a way for attackers to unlock an Android phone that is protected using a password, as revealed by a security researcher using the pseudonym jgor.

The vulnerability (CVE-2015 with 3860) only affects recent Android devices, running OS version 5.0.0 to 5.1.0, and can be exploited by attempting to authenticate to the lockscreen using a very long passcode while the camera app is open. The vulnerability only works when the lockscreen is protected by a passcode and is not present on devices that lock with PIN numbers or specific patterns. According to jgor, an attacker would need to have physical access to the phone for this flaw to be actively exploited. The basic steps to carry out such an attack are as follows: To begin with, the attacker would first need to create a long passcode. According to jgor, this can be achieved by using the emergency call window while the lockscreen is active. Attackers can type just one character at a time, or copy and paste a small portion over and over again until the field is full. Once a long text has been copied to the phone's clipboard, the attacker can then open the camera app, which for Android 5.x can be done from the lockscreen by swiping up on the camera icon (which is always active). With the camera open, attackers can then pull down the notification shade, and attempt to access the phone's settings section. This automatically causes the phone to prompt the user for a passcode, and the attacker can then provide their long passcode, previously created and stored in the phone's clipboard. Entering this text will destabilize the phone, and eventually cause the camera to crash. When this happens, the lockscreen is removed, and the attacker is redirected to the home screen from where they can extract the desired data. Google was notified of the vulnerability in late June, and has released Android 5.1.1 in early August to fix the problem. CVE-2015-3860 is also one of the security patches included in Google's first batch of over-the-air security updates .Android 5.x Lockscreens are bypassed with long random passwords










 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS