Last month, Google announced that a monthly patch cycle went input, which it first updates for Stage Fright leak were released. During the round patch of September, the Internet giant nine vulnerabilities fixed, two of which are labeled as critical.
Through Critical vulnerabilities an attacker could execute code remotely on the device, for example by sending an MMS message. One of these critical vulnerabilities had already actively attacked before the update was available. The other critical vulnerability relates to one of the Stage Fright leaks last month not fully been patched. The updates are only for Nexus devices and are over-the-air (OTA) are offered.
The update that Google has released the Critical Stage Fright flaw in Android does not work, say researchers from security firm Exodus Intelligence . However, Google will continue to roll out the faulty update, so let them know on their own blog. Through Stage Fright an attacker could install malicious apps on Android phones by just sending an MMS message.
On July 31, Jordan Gruskovnjak researcher claimed that there was a serious problem with the proposed patch of Google.Since the update itself had not yet been rolled out, the investigator could not confirm his suspicions. Last week, Google released the update finally out so Gruskovnjak could test whether the Stage Fright leak was indeed completely solved or not.Eventually he managed to create an MP4 file which the update could circumvent and to crash the device. The researcher warned Google on 7 August, but received no response.
Then Exodus Intelligence decided to publish details about the issue. The company states that they are probably not the only ones who have discovered that the update does not solve the problem entirely. In addition, would Stage Fright Detector app from Zimperium, the company that discovered the vulnerability, incorrectly indicate that users are safe, even if that is not the case. Meanwhile work Exodus Intelligence and Zimperium together to improve the detection of the app. However, Google still has not responded.
US customers of telecom provider T-Mobile have become the target of a sophisticated SMS phishing attack. The customers received a text message in which she was promised a discount of $ 20 when they opened the attached link.
The link pointed to a phishing page where to set the phone and the user's password is requested, and the last four digits of the social security number and PIN. After the data were completed, they got to see a message that the discount was processed and the official website of T-Mobile was loaded, reports anti-virus company Malwarebytes .
On Reddit allows an employee of T-Mobile know that the criminals behind the attack trying to get online access. Then they change the sim and let those expensive calls to premium numbers. Depending on how fast the scam is noted shin injury to the user in the hundreds or thousands of dollars. According to the employee gets them to deal with this every day.
This week it was announced that there was a very serious leak is present in Android which allows an attacker installed on millions of Android phones malware by only sending a single MMS message. Stage Fright, such as the vulnerability is known, however, is also to attack in other ways, according to the Japanese anti-virus company Trend Micro .
Security Zimperium Stage Fright made known this week. Trend Micro says that it has also found the same vulnerability independently of Zimperium and on May 19 of this year has been reported to Google. This implies that at least two parties have discovered a critical vulnerability of this magnitude and this then Google decided to report.
Attack Vectors
Trend Micro, however, that there are more ways to use Stage Fright. In addition to sending an MMS message, an attacker can use an app to attack the vulnerability, and the use of a website. The vulnerability is caused by the way the Android media server handles MP4 files. This allows an attacker to cause a heap overflow and then execute arbitrary code such as installing malware.
In addition to sending a malicious MP4 file from an MMS message, it is also possible to embed such a file in a Web site or by allowing an app to open, and thereby infect an Android phone with malware. Google has already rolled out an update, but many Android users for patches depend on their telecom provider or manufacturer of the device if the device is still supported.According to Trend Micro, the problem in Android version 4.0.1 to 5.1.1, which represents 94% of all Android devices.
Researchers have discovered a serious vulnerability in Android which makes it possible to gain access to devices simply by sending an MMS message. Then an attacker can steal information, read emails, activate the microphone and perform other tasks. The vulnerability is in Stage Fright, a media library that handles various popular media formats.
Security Zimperium discovered vulnerability in the Android part, that the self worst Android leak calls so far. An attacker only needs namely to send an MMS message to execute code on the device. It is thereby even possible to remove the message before the user gets to see it. Only the acknowledgement is all that is visible. The researchers warn that the vulnerability is very serious, because there is no interaction from the victim is required.
Estimates suggest that 950 million Android devices running risk. The problem is particularly acute among Android versions Jelly Bean, which is about 11% of all Android devices. Zimperium warned Google that has already rolled out patches for Android. In many cases, telecoms providers and manufacturers are, however, responsible for distributing updates to their users and the security company also fears that it may take a long time before everyone is protected.
Two manufacturers, however, are a positive exception. Meanwhile the Black Phone Silent Circle is patched and Mozilla Firefox is protected from the issue. At the upcoming Black Hat conference in Las Vegas will have more details about the vulnerability are announced.