Android smartphones can be hacked over Wi-Fi

qualcomm snapdragon
(Image credit: Shutterstock.com)

Nearly all Android mobile phones and other gadgets could be at risk of being hacked simply by connecting to a Wi-Fi network, new security research has warned.

Devices powered by Qualcomm's Snapdragon family of processors are susceptible to the threat, which would allow hackers to gain access to a device simply by connecting to the same Wi-Fi network.

Snapdragon processors can be found in most Android phones on the market today, meaning millions of devices may be potentially open to attack.

Over the air

Known together as "QualPwn", the two flaws can be exploited "over the air", meaning they only need to be close to the victim, meaning a hacker wouldn't even need to be in the same room as the target to be able to access their device. 

The issues were found by Tencent Blade, the security arm of Chinese gaming giant Tencent, and were revealed at the Black Hat cybersecurity event in Las Vegas this week.

Both exploit flaws in how the Snapdragon hardware connects to Wi-Fi networks and stays secure when online, meaning that once connected, third-parties could send malicious data packets over the air and then run code that could allow them full control over a victim's device.

Tencent Blade added that pretty much all devices powered by the Snapdragon 835 or 845 will be at risk, with the Google Pixel 2 and Pixel smartphones used to highlight the flaws in its report.

Qualcomm says it had released a patch addressing the flaw, and says it has made its licensees have been alerted to allow them to prepare fixes, with the company noting that its investigations found nearly all Snapdragon kit is affected.

QualPwn has now been patched by Google latest August 2019 Android security update, and users are being urged to update as soon as possible.

Via The Register

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Phone & Communications
ThinkPhone 25 by Motorola
I reviewed the ThinkPhone 25 by Motorola and while it's not as fast as its predecessor, it's the superior phone in so many ways
FRITZ!Box 7690 WiFi 7 Router
FRITZ!Box tries to embrace both business and home customers with its new 7690 router
Ulefone Armor Pad 4 Ultra Thermal
Other than screen reflection, I’m still looking for the downside to the Ulefone Armor Pad 4 Ultra Thermal tablet
Unihertz Tank Pad 8849
Carrying the Unihertz Tank Pad 8849 provided me with a full workout
Doogee Fire 6
The Doogee Fire 6 is another rugged retro SoC phone that fails to justify its cost or your interest
AGM H Max
AGM H Max rugged phone review
Latest in News
Nvidia geforce rtx 3050
RTX 5050 rumors detail full spec of desktop graphics card, suggesting Nvidia may use slower video RAM – but I wouldn’t panic yet
OnePlus 13
OnePlus is ditching the Alert Slider for an iPhone-style customizable button - and I’ll be sad to see it go
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
Q Acoustics Q SUB80, QSUB100 and QSUB120 subwoofers
Q Acoustics wants to bring the bass to your post-Oscars movie catch-up
Hospital
Major Oracle outage hits US Federal health record systems
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem