Showing posts with label Android Leak. Show all posts
Showing posts with label Android Leak. Show all posts

Wednesday, 4 November 2015

Critical Android Leak Fixes In Nexus Devices



During the patch cycle is from November Google poem multiple critical vulnerabilities in the Android version of Nexus devices, allowing an attacker to execute remote code on smartphones and tablets. Just as Microsoft is also Google each month with security updates.

It is in this case for updates to Nexus devices. The updates November fix seven vulnerabilities, two of which are labeled as critical. Through Critical vulnerabilities an attacker could execute code remotely on the device, for example by sending an MMS message, or if the user opens an e-mail or website. These are two leaks in the media server and libutils. The remaining five vulnerabilities, including one in the Stage Fright library, have a lesser impact.

According to Google, Android has several security measures that reduce the likelihood that Android leaks can be attacked successfully. For example, there are anti-exploit measures added to newer versions Android. In addition, search the Android Security Team via Verify Apps and SafetyNet to potentially harmful applications. Further send Google Hangouts, and Messenger will not automatically media to processes such as media server.

Updates are over-the-air (OTA) offered and are also available as firmware download. When the updates for the Android handsets from other manufacturers appear is unknown.

Wednesday, 5 August 2015

New Android Devices Leak Late Restart Endlessly


Researchers have discovered a new vulnerability in Android which could allow an attacker to restart the unit. In the event it is attacked leak via an app, it is possible to restart to endlessly leave the device. The problem is in the media server of Android, which also previously the Stage Fright leak was discovered, and a vulnerability that sets almost unusable makes.

Also this leak was from the Japanese anti-virus company Trend Micro detected and is present in Android 4.0.1 to 5.1.1 Lollipop. That equates to 89% of Android users. To carry out the attack must play a user to a malicious website an MKV file or install an app that contains the file. In the case of the attack on a media server app is running will end up in an endless loop. The system will eventually be so slow that the system will reboot or the battery expires.

If the attack performed via a website, a user must first play the movie itself. The impact can be especially great when a malicious app. The app can set that starts right at the loading of Android and can then leave as endless reboot the device. In this case, users are not able to remove the app in question, unless the product is launched in Safe mode.

The problem was reported to Google on May 19. On July 31, the Android security team said that there was a security update available. In many cases, Android users for updates depending on their phone company or the manufacturer of their device.Thus it may take longer for updates to be rolled out to users. To our knowledge, the vulnerability is not attacked in the "wild".

Thursday, 30 July 2015

New Android Phones Leak Is Virtually Useless



Researchers have discovered a vulnerability in Android devices allow an attacker can make it as good as useless. The vulnerability, which can be attacked through both websites as a rogue app, ensures that the user can not hear or see that there is a call or a text message is sent. Also, calls can not be accepted.

In case the attack is carried out via a malicious app can crash the operating system. When the app first set to start automatically upon loading the operating system, would thus arise a continuous loop of crashes. Each time the machine crashes because the user's phone and restart the app is loaded again and release Android then crash. Further, the telephone such as that it is no longer locked, to be unlocked.

The problem is in Android 4.3 to Android 5.1.1, which together more than half of all Android devices. According to researchers at Trend Micro appears to be the vulnerability this week announced Stage Fright leak . Both vulnerabilities arise due to the way Android handles media files, although the way these files reach different user. Google was on May 15 informed about the problem, but still has not rolled out updates.