Skip to main content

900 Million Android Devices Affected by Critical 'QuadRooter' Vulnerability: Report


900 Million Android Devices Affected by Critical 'QuadRooter' Vulnerability: Report

Highlights

  • If exploited QuadRooter flaw gives attackers complete control of devices
  • QuadRooter flaw found in software drivers that ship with Qualcomm SoCs
  • Qualcomm claims that patches were released for the flaw
A new Android flaw has been reported by security researchers that is claimed to affect roughly 900 million Android devices. Check Point mobile research team first reported the issue and claims that it affects all devices using Qualcomm chipsets.
Dubbed 'QuadRooter', it is said to be a set of four vulnerabilities affecting Android devices built on Qualcomm chipsets. The research team explains that if any one of the four vulnerabilities is exploited, an attacker can trigger privilege escalations for the purpose of gaining root access to a device. The team also claimed that the QuadRooter vulnerabilities are present in software drivers that ship with Qualcomm SoCs. "Any Android device built using these chipsets is at risk," notes Check Point.
Qualcomm informed ZDNet that patches for the issue were released to "customers, partners, and the open source community between April and the end of July."
One of the biggest concerns with the QuadRooter vulnerability is that the buggy software is pre-installed on devices at the point of manufacture, and can only be fixed via security patch released by the carrier or distributor. "Distributors and carriers issuing patches can only do so after receiving fixed driver packs from Qualcomm," adds Check Point in a blog post.
"An attacker can exploit these vulnerabilities using a malicious app. Such an app would require no special permissions to take advantage of these vulnerabilities, alleviating any suspicion users may have when installing," explains Check Point mobile research team.
Some of the popular devices said to be affected by the new QuadRooter flaw include BlackBerry Priv, Google Nexus 5X, Nexus 6P, HTC 10, LG G5, Moto X, OnePlus 3, and Samsung Galaxy S7 among others. The team also claimed that secure phones - Blackphone 1 and Blackphone 2 - are also likely to be affected by this vulnerability. Adam Donenfeld, Lead Mobile Security Researcher at Check Point, revealed the vulnerability at a recent Def Con security conference in Las Vegas.
"If exploited, QuadRooter vulnerabilities can give attackers complete control of devices and unrestricted access to sensitive personal and enterprise data on them. Access could also provide an attacker with capabilities such as keylogging, GPS tracking, and recording video and audio," adds the team.
A Qualcomm spokesperson told ZDNet, "Qualcomm has a significant position in the development chain, in that a phone maker isn't taking the Android open-source code directly from Google, they're actually taking it from Qualcomm. No-one at this point has a device that's fully secure. That basically relates to the fact that there is some kind of issue of who fixes what between Qualcomm and Google."
Check Point recommends some best practices to keep Android devices safe from such attacks like downloading and installing the latest Android update; examine any app installation request before accepting; avoid side-loading Android apps, and read permission requests when installing any apps among others.

Comments

Popular posts from this blog

Sri Lanka Police Arrest Teen for Hacking President's Website to Postpone ExamAgence

  30 August 2016 Sri Lanka's police Monday arrested a 17-year-old teenager for hacking into President Maithripala Sirisena's official website and posting a message calling for the postponement of A-level examinations. The unnamed boy was taken into custody under the Computer Crimes Act and on conviction faces a fine of LKR 300,000 ($2,000) and up to three years in jail. "We traced the hack to his home in Kadugannawa," a police official said referring to a town about 100 kilometres (62 miles) east of the capital Colombo. "The website was crippled over the weekend after the attack." On Monday, the president's official site was up and running again. The attacker had removed the home page of the website and replaced it with a demand that the President postpone the ongoing GCE Advanced Level examinations or step down. Sri Lankan websites had been hacked in the past, but this was the first time that a teenager had been arrested under th...

Hello Moto: A Look Back at Six Classic Moto Phones

  12 December 2016 HIGHLIGHTS Motorola was the first company to ship a cellphone Its biggest hit was the Moto RAZR V3 Today, Motorola is a part of Chinese electronics giant Lenovo Recently, we relived the past with Nokia’s most memorable phones of all time. Although there may be a lot of fanboys and fangirls of the Finnish brand, many have equally strong feelings for the daddy of all mobile phone brands - Motorola. Its name will forever be etched in history as the  first company  to sell a mobile phone - the DyanTAC 8000X - in 1983. Since then, Motorola has been an easily identifiable brand to almost everybody in the world. Its designs were often strikingly unique and at the same time, Motorola phones often gave out a vibe that these devices mean business. Today, we’ve handpicked some of the most memorable Motorola phones we’ve come across. Here are our picks for the six most memorable Motorola phones of all time. 1) Motorola ...

ChatSim 2 Launched With Unlimited Internet Access and Messaging, to Be Showcased at MWC 2018

25 February 2018, Shivashish Bhunia Before Reading this up,  just check out my Bestie's Page For Amazing Quotes and Poetry Content!  https://www.theparadoxwhowritez.blogspot.com HIGHLIGHTS The second-gen variant offers access for all mobile apps in its core plan World premiere of ChatSim 2 will take place at MWC 2018 in Barcelona It provides unlimited to messaging apps like WhatsApp and WeChat SIM card provider ChatSim on Thursday announced the launch of its latest ChatSim 2 SIM card in Milan, Italy. The second generation of the company's proprietary SIM card now claims to offer Internet surfing with "free and unlimited data traffic." The SIM card can provide data access without limitations, roaming charges, or Wi-Fi connectivity. The annual plan also lets you send text messages across 165 countries. ChatSim 2 will have its world premiere at Mobile World Congress 2018 in Barcelona from February 26-March 1, and more ...