Google is reported to have repaired another security bug that affects almost all versions of Android from 2.3 to 5.1.1. According to the Trend Micro security company, vulnerability could be used to abuse the privacy of the owners of the device.
The error is most likely repaired in a next Google security update on Nexus devices.
The error could allow a hacker to abuse the Android Mediaserver program to spy on the owners of the device.
It can also add a large list of vulnerabilities resulting from this particular Android feature, which was at the root of one of the seven bugs in the Stagefright media library.
Trend Micro researcher, Wish Wu he stressed yesterday that Google has added a solution to the latest bug, also known as CVE-2015-382, in the code of the Android Open Source Project 1 of August.
Google itself reports the flaw as being of the highest severity.
Unlike Stagefright, which can be tapped by simply sending a malicious multimedia file to Android devices, in this case an attacker should cheat his victims to install a malicious application.
If this is achieved, "the attacker will be able to execute code with the same rights that Mediaserver already has as part of its normal routine," Wu said.
"As the Mediaserver feature handles a wide range of media-related tasks, including taking photos, reading MP4 files, and recording video, protecting the victim's privacy can be in immediate danger," he added.
Trend Micro also revealed a minority defect that again affects Mediaserver and could be used to make a device perform endless restarts.
Let's say that Android security no longer inspires any confidence especially from the revelation of Stagefright onwards.
Google has since released bug fixes on August 5, but immediately after admitting that the solution does not completely repair the weaknesses and promised to release another update in September.
George is still wondering what he is doing here….

