Thanks to a security flaw, Android apps had the ability to take photos and record conversations without users knowing it.
According to a bombshell reportreleased Tuesday by cybersecurity firm Checkmarx, a major Android flaw gave attackers shockingly broad permissions to a phone without consent from users. The flaw, dubbed CVE-2019-2234, allowed an app developer to gain unparalleled access to a device’s camera, turning a user's phone into a spying device. Checkmarx was able to uncover all of these vulnerabilities through a fake weather app it created.
An attacker could silence the camera shutter to hide the fact that it was recording video and taking photos without consent. These actions could even be taken when the malicious app was closed, with the screen off and the phone locked.
The flaw also gave an attacker access to stored media on a device, as well as the GPS data on photos and videos in its library. And it allowed an app developer to eavesdrop on both sides of a phone conversation and record audio.
Yes, it gets worse. A phone’s proximity sensor could be used to let the attacker know when the phone was held up to a user’s ear for a phone call or when the phone was lying face down so the open camera app couldn’t be detected while taking photos or recording video.
An attacker was even able to upload images and video from the phone to a server if a user granted the app permission to access the device’s storage.
Checkmarx first discovered the flaw over the summer while researching the Google Camera app on a Google Pixel 2 XL and Pixel 3. Further investigation uncovered the same vulnerabilities in "camera apps of other smartphone vendors in the Android ecosystem," including Samsung.
Among the most startling aspects of this flaw is the fact that the attackers were able to access a phone’s camera and mic without a user first giving permission to the app. Even the recently viral Facebook bug, which forced the iPhone's camera open, required user permission before accessing the camera.
According to Checkmarx’s report, it first contacted Google about the flaw in early July. Samsung confirmed it was also affected by the vulnerabilities in late August. Both companies approved the publication of Checkmarx’s report this month.
“We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure,” said a Google spokesperson in a statement provided to Checkmarx. “The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners.”
SEE ALSO: AirPods Pro and Android: Is it worth it?In a statement to Arstechnica, Checkmarx Director of Security Research Erez Yalon speculated that the flaw may arise from Google granting its voice assistant access to a device’s camera.
Besides Google and Samsung, it’s unclear how many, if any, other Android phone manufacturers were affected by the vulnerability.
With just those two companies, however, this flaw had the ability to affect hundreds of millions of smartphone owners around the world.
Android device owners can protect themselves by making sure their smartphones are updated to the latest version of the operating system.
Copyright © 2023 Powered by
Android flaw allowed attackers to spy on users through phone camera-声闻过情网
sitemap
文章
57866
浏览
27
获赞
4
Google says China and Iran tried to hack Biden and Trump's campaigns
Google has announced it has identified state-sponsored hacking attempts upon both Biden and Trump'sStudy reveals the simple way people get around Facebook's fact
Recently, Facebook has been taking a harder stance on misinformation.The company banned content relaWhat to expect at Google's 'Launch Night In' 2020 hardware event
On September 30, Google will hold its annual hardware event. Due to the pandemic, the event will beMadame Tussauds spins high drama, removes Harry and Meghan from Royal Family
Madame Tussauds is heating up some high drama, physically removing statues of Harry and Meghan fromUber Boat takes over London commuter ferry for water rides
UPDATE: Aug. 3, 2020, 10:03 a.m. BST Uber Boat has launched in London, setting sail on the River Tha8 surprising things I learned after testing an electric bike for a year
For a little over 12 months, I've been testing the same model of the same $4,000 electric bike, theNew tool makes it easy to see which websites are in bed with Facebook
The internet is a labyrinthian place, and Facebook is hiding around almost every corner. A new tool,Spotify, Epic join coalition to change Apple's App Store practices
A number of companies have formed a non-profit organization with the goal of forcing Apple to changeGoogle launches new AR tool to visualise social distancing rules
We're all adjusting to a new, socially distant way of life. Here to help with that is a new tool froSomeone hired Mark McGrath and Anthony Scaramucci to break up with their boyfriend on Cameo
A man named Brayden has had a rollercoaster of a past few days. Bad news: His relationship ended. GoHow to watch Apple's iPhone 12 event
It’s finally here, folks. Apple is expected to announce the highly anticipated iPhone 12 at itMask emoji on Apple's iOS 14.2 is a lot more cheerful than before
Apple is doing its (tiny) share of making mask-wearing a little less dreary. In the next version ofChase bank tried to be relatable on Twitter and got absolutely dunked on
Brands, may we remind you for the umpteenth time, that if you're trying to get #relatable on TwitterThis swing
If you're steeling yourself for arguments over the Christmas table this year, bookmark this now. WheReport: Tesla reduces used
Tesla has reduced the length of its used-car warranty to one year or 10,000 miles.As Electrek report