Another gaping Android flaw could affect millions of devices

Stagefright

A new spin on the Stagefright flaw – which shot to fame as a gaping Android vulnerability last year – is on the scene and could potentially cause users of Google's mobile OS a good deal of grief.

The exploit, which goes by the name of Metaphor, was revealed by Northbit, an Israeli security consultancy, and could potentially be wielded against millions of Android phones across the globe.

The exploit can be used against devices running Android versions 2.2 through to 4.0, and also Android 5.0 and 5.1 (Lollipop). Concerning the latter, it's clever enough to bypass ASLR (Address Space Layout Randomisation – a defensive memory protection measure).

As Northbit notes, it has been claimed that Stagefright was impractical to exploit in the wild due to mitigations built into the newer versions of Android, the main pillar of which is ASLR. But it seems these defences aren't as watertight as folks might previously have believed.

Nexus nobbled

Northbit has published a research paper detailing the exploit, and also a video showing it being used to compromise a Nexus 5 phone running Android 5.0.1, with the user in the demo getting hit simply by being lured into clicking a link to the exploit-laden website.

Apparently the security firm has also successfully leveraged the flaw against LG G3, HTC One and Samsung Galaxy S5 handsets (though slight modifications were needed to target different phones).

In its paper, Northbit concluded: "This research shows exploitation of this vulnerability is feasible. Even though a universal exploit with no prior knowledge was not achieved, because it is necessary to build lookup tables per ROM, it has been proven practical to exploit in the wild."

Chris Eng, Vice President of Research at Veracode, commented on the issue: "With the discovery of the 'Metaphor' vulnerability, 2016 is the third year in a row when a serious application exploit has been discovered which could impact millions of devices.

"Patching application vulnerabilities is especially challenging for the Android community with the number of different manufactures and carriers charged with the responsibility of issuing patches to devices. As with Stagefright, we anticipate that Google will be quick to issue a patch to resolve this problem. However, we hope that we don't see a replay of Stagefright 2.0 where many of the patches hadn't been rolled out to end-users."

Indeed, let's hope that action is taken promptly, and meanwhile, if you (or your employees) use an Android device, it might be worth taking some extra caution when clicking links. Although these days, vigilance is pretty much a constant need when it comes to links (and attachments).

Via: Wired

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Pro
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
HP Series 7 Pro 734pm during our review
I reviewed HP's Series 7 Pro 734pm and I'm obsessed with the sheer connectivity of this widescreen monitor
TSMC
TSMC announces huge US investment to boost AI development
Google Pixel 9 Pro
Google Password Manager may be set to introduce a nuclear option for its Android app
Latest in News
iPad Air M3
Apple updates iPad Air with powerful M3 chip and pairs it with Pro-level Magic Keyboard
Nvidia RTX 5070 Founders Edition GPU shown against a green and black backdrop
Nvidia RTX 5070 early pricing hints at plenty of GPUs at the MSRP – but I’ll believe it when I see it
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Guitar Hero Mobile
Activision shares first look at Guitar Hero Mobile and, yeah, it looks like AI slop
Web DDoS attacks see major surge as AI allows more powerful attacks
Pulchra Fellini in Zenless Zone Zero.
Zenless Zone Zero Version 1.6 will finally let you play as a furry gunslinger