{"id":144579,"date":"2019-07-25T04:42:20","date_gmt":"2019-07-25T01:42:20","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/android-vulnerability-lets-hackers-hijack-your-phone-with-malicious-videos\/"},"modified":"2019-07-25T04:42:20","modified_gmt":"2019-07-25T01:42:20","slug":"android-vulnerability-lets-hackers-hijack-your-phone-with-malicious-videos","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/android-vulnerability-lets-hackers-hijack-your-phone-with-malicious-videos\/","title":{"rendered":"Android vulnerability lets hackers hijack your phone with malicious videos"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>If you use a phone running any version of Android between 7.0 and 9.0 (<a href=\"https:\/\/thenextweb.com\/opinion\/2016\/12\/09\/android-nougat-rolling-surprisingly-quickly-change\/\" target=\"_blank\" rel=\"noopener noreferrer\">Nougat<\/a>, <a href=\"https:\/\/thenextweb.com\/google\/2017\/08\/21\/android-o-delightfully-named-oreo\/\" target=\"_blank\" rel=\"noopener noreferrer\">Oreo<\/a>, or\u00a0<a href=\"https:\/\/thenextweb.com\/google\/2018\/08\/07\/google-officially-names-android-9-pie-rolling-out-to-pixels-today-and-other-devices-this-fall\/\" target=\"_blank\" rel=\"noopener noreferrer\">Pie<\/a>), you ought to immediately install the latest security update \u2013 or risk getting your handset hijacked by devious video malware.<\/p>\n<p>The culprit is a vulnerability in the aforementioned Android versions (<span><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-2107\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">CVE-2019-2107<\/a>)<\/span>, which enables hackers to remotely execute arbitrary code by sneaking in \u201cspecially crafted files,\u201d like videos laced with a malicious payload. Once a victim has opened the file, attackers can gain access to their device.<\/p>\n<p>Developer\u00a0<span>Marcin Kozlowski has already\u00a0<a href=\"https:\/\/github.com\/marcinguy\/CVE-2019-2107\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">uploaded<\/a> a proof of concept\u00a0for the\u00a0attack vector on GitHub. \u201cYou can own the mobile [device] by viewing a video with [the malicious] payload,\u201d Kozlowski wrote in the documentation.<\/span><\/p>\n<p>\u201cA possible\u00a0attack vector is opening an unmodified malicious video file,\u201d Kozlowski told TNW. \u201cSuch files can be sent for example via email (the\u00a0Gmail app\u00a0loads video with Android\u2019s stock video player, unless you changed it to another player).\u201d<\/p>\n<p>Fortunately, there are some caveats that make the exploit difficult (but not impossible) to pull off.<\/p>\n<p>For one, the attack will only work if victims load the infectious video in its unmodified state.<\/p>\n<p>In fact, people in the Twitterverse have already speculated that sending the malware via services that re-encode the video \u2013 like YouTube,\u00a0WhatsApp, or Messenger \u2013 will stifle attacks.<\/p>\n<p>Kozlowski seconds this assumption. \u201c<span>If the video would be touched or re-encoded, which I think messengers do, it would stop the attack,\u201d he told TNW.<\/span> \u201cRe-uploading should break the exploit,\u201d ESET malware researcher <a href=\"https:\/\/thenextweb.com\/google\/2018\/11\/21\/500000-android-users-downloaded-malware-made-by-one-developer\/\" target=\"_blank\" rel=\"noopener noreferrer\">Lukas Stefanko<\/a> further told TNW.<\/p>\n<h2>Google has already dropped a fix<\/h2>\n<p>While the vulnerability\u00a0is pretty severe, the good thing is that Google <a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-07-01\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">has already rolled out<\/a> a security update that fixes the issue.<\/p>\n<p>Indeed, the kink in question was one of the three Media Framework vulnerabilities Google addressed in its July Security Bulletin. \u201c<span>The most severe vulnerability in this section could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process,\u201d the company wrote.<\/span><\/p>\n<p>It\u2019s difficult to estimate how many devices are at risk, but Google <a href=\"https:\/\/twitter.com\/Android\/status\/1125822326183014401\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">bragged<\/a> there are over 2.5 billion active Android handsets back in May 2019. Out of those, nearly 58 percent (about 1.5 billion) are running versions of Android susceptible to this vulnerability, according to Google\u2019s <a href=\"https:\/\/developer.android.com\/about\/dashboards\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">distribution dashboard<\/a>.<\/p>\n<p>Of course, there\u2019s no telling how many of those phones have been patched with the latest security update. Google didn\u2019t specify the exact number, but a spokesperson told TNW its security team hasn\u2019t seen any evidence of this vulnerability being exploited in the wild.<\/p>\n<p><figure class=\"post-image post-mediaBleed alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1231536 lazy\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" alt=\"\" width=\"899\" height=\"609\" sizes=\"auto, (max-width: 899px) 100vw, 899px\" data-src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Screen-Shot-2019-07-24-at-14.09.20.png\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Screen-Shot-2019-07-24-at-14.09.20.png 899w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Screen-Shot-2019-07-24-at-14.09.20-280x190.png 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Screen-Shot-2019-07-24-at-14.09.20-399x270.png 399w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Screen-Shot-2019-07-24-at-14.09.20-199x135.png 199w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Screen-Shot-2019-07-24-at-14.09.20-796x539.png 796w\"\/><\/figure>\n<\/p>\n<p>Earlier in July, Symantec <a href=\"https:\/\/www.symantec.com\/blogs\/expert-perspectives\/symantec-mobile-threat-defense-attackers-can-manipulate-your-whatsapp-and-telegram-media\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">uncovered<\/a> an attack vector that made it possible to manipulate media files \u2013 like videos and images \u2013 on WhatsApp and Telegram. Unlike this Android vulnerability though, the malware Symantec detailed didn\u2019t allow for remote code execution or device takeover.<\/p>\n<p>If you\u2019re running an affected Android version, your best bet would be to update your operating system as soon as possible. Google has <a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-07-01\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">already released<\/a> a security update (2019-07-05) that patches this issue. Follow <a href=\"https:\/\/support.google.com\/pixelphone\/answer\/4457705\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">these steps<\/a> to protect yourself.<\/p>\n<p class=\"post-article-read-next\">\n    <b>Read next:<\/b><br \/>\n    <a class=\"gtm-article-read-next\" data-event-category=\"Article\" data-event-action=\"Next post\" data-event-label=\"\" data-event-non-interaction=\"true\" href=\"https:\/\/thenextweb.com\/facebook\/2019\/07\/24\/facebook-gets-away-with-5b-ftc-fine-for-leaking-your-data\/\"><br \/>\n        Facebook gets away with $5B FTC fine for leaking your data    <\/a>\n<\/p>\n<\/p><\/div>\n<p><script async src=\"http:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/security\/2019\/07\/24\/google-android-vulnerability-malicious-video\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] If you use a phone running any version of Android between 7.0 and 9.0 (Nougat, Oreo, or\u00a0Pie), you ought to immediately install the latest security update \u2013 or risk getting your handset hijacked by devious video malware. The culprit is a vulnerability in the aforementioned Android versions (CVE-2019-2107), which enables hackers to remotely execute &hellip;<\/p>\n","protected":false},"author":1,"featured_media":144580,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-144579","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/144579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=144579"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/144579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/144580"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=144579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=144579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=144579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}