New vulnerability affects 55% of Android devices

At the USENIX WOOT 2015 Security Conference this weekend in Washington, Peles and Roee Hay presented a new zero-day vulnerability that affects Android devices.Android Security

In their work titled One Class to Rule Them All, the two researchers with X-Force Application Security IBM Team presented a PoC of CVE-2014-3153, a vulnerability they discovered in Android's OpenSSLX509Certificate class.

With this vulnerability an attacker can give greater privileges to an application, but also gain root privileges throughout the phone.

Attackers can use the vulnerability to replace authentic ones with fake ones!

According to the researchers, an attacker could easily use this vulnerability to download malware APK on the user's device, and then use them to replace genuine apps, such as the Facebook app, as shown in the video below.

The impact of privilege escalation with CVE-2014-3153 is not limited to overwriting authentic applications. The they could also download whatever they want from the user's device, and spy on the owner, who will never know anything, as everything happens in the background.

According to the researchers, all versions of Android 4,3 with up to 5,1 are affected, namely Jelly Bean, KitKat, and Lollipop. The latest version M is also vulnerable. This represents approximately 55% of all Android devices.

See PoC

https://www.youtube.com/watch?v=VekzwVdwqIY

Note: Such vulnerabilities make it imperative to find a direct distribution solution for Android updates. 2015 Google's system of updates is unacceptable!

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).