Android glitch allows hackers to bug phone calls

Attack pierces defenses on devices from HTC, Samsung, Motorola, Google


Computer scientists have discovered a weakness in smartphones running Google's Android operating system that allows attackers to secretly record phone conversations, monitor geographic location data, and access other sensitive resources without permission.

Handsets sold by HTC, Samsung, Motorola, and Google contain code that exposes powerful capabilities to untrusted apps, scientists from North Carolina State University said. These “explicit capability leaks” bypass key security defenses built into Android that require users to clearly grant permission before an app gets access to personal information and functions such as text messaging. The code making the circumvention possible is contained in interfaces and services the device manufactures add to enhance the stock firmware supplied by Google.

“We believe these results demonstrate that capability leaks constitute a tangible security weakness for many Android smartphones in the market today,” the researchers wrote in a paper (PDF) scheduled to be presented at next year's Network and Distributed System Security Symposium. “Particularly, smartphones with more pre-loaded apps tend to be more likely to have explicit capability leaks.”

The researchers created a diagnostic app dubbed Woodpecker and ran it on eight smartphones from the four vendors. The most vulnerable was HTC's EVO 4G device, which was found to leak eight functions, including its precise geographic location finder, camera, text message service, and audio recorder. HTC's Legend came in second with six leaks. Samsung's Epic 4G contained three leaks, including the ability to wipe data and applications off the handset. Google's Nexus One and Nexus S contained one leak.

Unlike out-of-the-box iPhones, which allow users to install only apps that have been approved by Apple, the official Android Market performs no security checks on the wares it offers. To compensate, Google built the permission-based security model into the mobile OS to give users control over the personal information apps get to access. Before a new program runs for the first time, it lists the sensitive resources it will access. Users who are uncomfortable with the permissions then have an opportunity to cancel the installation.

The researchers found that the manufacturer-supplied enhancements offer a way to circumvent this permissions-based model. In a video demonstration, they show how an app they designed is able to access audio-recording and SMS functions on an EVO 4G without first getting approval from the user. As a result, the app is able to turn on a recorder that collects nearby audio or phone conversations. The app is also able to send unauthorized text messages.

The researchers said both Google and Motorola have confirmed the vulnerabilities in their handsets, but that HTC and Samsung “have been really slow in responding to, if not ignoring, our reports/inquiries.”

The North Carolina State University scientists are the same team that has uncovered other serious security vulnerabilities in Android-powered smartphones, including the infiltration of at least 12 malicious apps in the Android Market. The data-stealing programs festered there for months and racked up hundreds of thousands of downloads. They were removed only after the researchers alerted Google to their presence.

The researchers say other Android handset models may also be vulnerable to the latest permissions-bypass attack. ®

Follow dangoodin001

Similar topics


Other stories you might like

  • Battlefield 2042: Please don't be the death knell of the franchise, please don't be the death knell of the franchise

    Another terrible launch, but DICE is already working on improvements

    The RPG Greetings, traveller, and welcome back to The Register Plays Games, our monthly gaming column. Since the last edition on New World, we hit level cap and the "endgame". Around this time, item duping exploits became rife and every attempt Amazon Games made to fix it just broke something else. The post-level 60 "watermark" system for gear drops is also infuriating and tedious, but not something we were able to address in the column. So bear these things in mind if you were ever tempted. On that note, it's time to look at another newly released shit show – Battlefield 2042.

    I wanted to love Battlefield 2042, I really did. After the bum note of the first-person shooter (FPS) franchise's return to Second World War theatres with Battlefield V (2018), I stupidly assumed the next entry from EA-owned Swedish developer DICE would be a return to form. I was wrong.

    The multiplayer military FPS market is dominated by two forces: Activision's Call of Duty (COD) series and EA's Battlefield. Fans of each franchise are loyal to the point of zealotry with little crossover between player bases. Here's where I stand: COD jumped the shark with Modern Warfare 2 in 2009. It's flip-flopped from WW2 to present-day combat and back again, tried sci-fi, and even the Battle Royale trend with the free-to-play Call of Duty: Warzone (2020), which has been thoroughly ruined by hackers and developer inaction.

    Continue reading
  • American diplomats' iPhones reportedly compromised by NSO Group intrusion software

    Reuters claims nine State Department employees outside the US had their devices hacked

    The Apple iPhones of at least nine US State Department officials were compromised by an unidentified entity using NSO Group's Pegasus spyware, according to a report published Friday by Reuters.

    NSO Group in an email to The Register said it has blocked an unnamed customers' access to its system upon receiving an inquiry about the incident but has yet to confirm whether its software was involved.

    "Once the inquiry was received, and before any investigation under our compliance policy, we have decided to immediately terminate relevant customers’ access to the system, due to the severity of the allegations," an NSO spokesperson told The Register in an email. "To this point, we haven’t received any information nor the phone numbers, nor any indication that NSO’s tools were used in this case."

    Continue reading
  • Utility biz Delta-Montrose Electric Association loses billing capability and two decades of records after cyber attack

    All together now - R, A, N, S, O...

    A US utility company based in Colorado was hit by a ransomware attack in November that wiped out two decades' worth of records and knocked out billing systems that won't be restored until next week at the earliest.

    The attack was detailed by the Delta-Montrose Electric Association (DMEA) in a post on its website explaining that current customers won't be penalised for being unable to pay their bills because of the incident.

    "We are a victim of a malicious cyber security attack. In the middle of an investigation, that is as far as I’m willing to go," DMEA chief exec Alyssa Clemsen Roberts told a public board meeting, as reported by a local paper.

    Continue reading

Biting the hand that feeds IT © 1998–2021