Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Wally Santana/Associated Press

More than a billion Android devices are vulnerable to second Stagefright bug

This time, an attack can happen just by previewing a song or video on your phone.

MORE THAN A BILLION Android devices are at risk from a flaw that can infect devices when they preview an audio or video file.

Mobile security company Zimperium Labs discovered two new vulnerabilities that could put these devices at risk. Called Stagefright 2.0, an attacker can use a specially-created MP3 or MP4 file to access an Android device’s code to track or take information or make changes remotely.

The same company discovered the original Stagefright bug and announced it back in July. That bug could see Android devices infected just by sending a text message to Google Hangouts or Messenger apps.

The issue lies with Android’s preview function, which processes the metadata within the files, and since Google Hangout and Messenger have been updated, the attack would be carried out through a web browser.

The vulnerability lies in the processing of metadata within the files, so merely previewing the song or video would trigger the issue. Since the primary attack vector of MMS has been removed in newer versions of Google’s Hangouts and Messenger apps, the likely attack vector would be via the Web browser.

The first vulnerability, found in the libutils code library, impacts almost every Android device as far back as 2008 while the second (libstagefright which is used to process media files) only affects those running Android version 5.0 and above.

However, there have been no examples where the flaws were exploited in public, and the details of said exploits have been kept private to prevent anyone from discovering it.

Zimperium Labs notified the Android Security Team of the issue back in August and an update has been shared with manufacturers. However, a fix for the second vulnerability hasn’t been provided yet.

While it is worrying that such flaws and vulnerabilities exist, the best way to keep yourself safe is to apply common sense when using your phone.

Always use approved apps, keep away from any sites or services that may look shady and don’t download content from unknown sources (for unapproved apps, you can check this by going into Settings > Security and making sure ‘unknown sources’ is turned off).

Read: Meet the man who managed to buy Google.com from Google >

Read: Use Tinder? There’s a big change on the way >

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
7 Comments
    Install the app to use these features.
    Mute Vinnie
    Favourite Vinnie
    Report
    Oct 2nd 2015, 8:59 AM

    People use Google Hangouts?

    120
    Install the app to use these features.
    Mute John Ó'Ríordán
    Favourite John Ó'Ríordán
    Report
    Oct 2nd 2015, 9:29 AM

    I love Google Hangouts. Its built in to all my friends phone, it’s free to use and it’s got a desktop version I can use at work so i don’t have to type on my phone.

    When I was abroad I used it a lot for it’s free voice and video calls. The group calls especially were very useful.

    Why wouldn’t you use it?

    52
    Install the app to use these features.
    Mute Paul Roche
    Favourite Paul Roche
    Report
    Oct 2nd 2015, 10:20 AM

    Best answer I can think of is my iPhone…

    17
    See 3 more replies ▾
    Install the app to use these features.
    Mute Brian Brian
    Favourite Brian Brian
    Report
    Oct 2nd 2015, 12:08 PM

    I have a potato here Paul. It’s nothing special but I have decided to put an “i” before it and a little logo of a half eaten apple. It’s yours for €800. Interested? Of course you are. Better get your tent out though cause the demand is huge!!!

    49
    Install the app to use these features.
    Mute Paul Roche
    Favourite Paul Roche
    Report
    Oct 2nd 2015, 1:34 PM

    You use Google Hangouts Brian?

    7
    Install the app to use these features.
    Mute Brian Brian
    Favourite Brian Brian
    Report
    Oct 2nd 2015, 5:30 PM

    Yes Paul I sure do. I find it very effective.

    9
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds