TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Major Flaw in Android Phones Would Let Hackers in with Just a Text

399 pointsby dynofuzalmost 10 years ago

36 comments

jimrandomhalmost 10 years ago
Summary: MMS messages can cause Android phones to decode video with libstagefright, which is a C++ library with vulnerabilities and insufficient sandboxing, leading to remote code execution without user interaction.<p>You can partially mitigate the risk by disabling auto-downloading of MMS messages in whichever app you have set to handle text messages, such as Messaging or Hangouts. THIS IS URGENT. While the precise details of the flaw have not been publicly disclosed, this disclosure is sufficient for a skilled person to rediscover the flaw, which means that there is a considerable risk that someone will systematically use it on all the phone numbers.
评论 #9956907 未加载
评论 #9956818 未加载
评论 #9958585 未加载
评论 #9959100 未加载
评论 #9959469 未加载
评论 #9959096 未加载
评论 #9960170 未加载
评论 #9957067 未加载
评论 #9958475 未加载
评论 #9957386 未加载
评论 #9961968 未加载
评论 #9956800 未加载
cosarara97almost 10 years ago
Google might have to rethink Android&#x27;s updating strategy, if vulnerabilities like this keep coming out. Of course it would be nice to never have to update some devices, but it&#x27;s not viable if they are: a) As complex as an Android phone and b) Connected to the internet&#x2F;phone network.
评论 #9954837 未加载
评论 #9955019 未加载
评论 #9961792 未加载
评论 #9954824 未加载
评论 #9967292 未加载
gueloalmost 10 years ago
&gt; Drake speculates that Stagefright has its excessive permissions and Internet access to satisfy some types of digital rights management processing or streaming playback.<p>Goddamn you Hollywood.
评论 #9957483 未加载
评论 #9956928 未加载
评论 #9956934 未加载
评论 #9957115 未加载
bitmapbrotheralmost 10 years ago
These look to be the flaws:<p><a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103276&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103276&#x2F;</a><p><a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103275&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103275&#x2F;</a><p><a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103274&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103274&#x2F;</a><p><a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103273&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103273&#x2F;</a><p><a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103272&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103272&#x2F;</a>
评论 #9956626 未加载
评论 #9957986 未加载
评论 #9958025 未加载
leephillipsalmost 10 years ago
Can I configure my phone to reject text messages with attached video? I&#x27;m thinking that would protect me from this exploit, plus, as a bonus, I wouldn&#x27;t get text messages with attached video.<p>EDIT: I appreciate the replies. I was really wondering if I can disable video attachments without disabling other MMS features such as pictures and long messages (in Android 4.3).
评论 #9955802 未加载
评论 #9955835 未加载
pwnnaalmost 10 years ago
I see a series of patches going on CyanogenMod (5 on 12.1 and only 3 on 12.0). Are there any more?<p>1. <a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103267&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103267&#x2F;</a><p>2. <a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103268&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103268&#x2F;</a><p>3. <a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103269&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103269&#x2F;</a><p>4. <a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103270&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103270&#x2F;</a><p>5. <a href="http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103266&#x2F;" rel="nofollow">http:&#x2F;&#x2F;review.cyanogenmod.org&#x2F;#&#x2F;c&#x2F;103266&#x2F;</a>
评论 #9959953 未加载
gueloalmost 10 years ago
If a two year old phone doesn&#x27;t get security patches is that enough for massive class action lawsuits? It&#x27;s a defective product.
评论 #9958388 未加载
评论 #9957158 未加载
Animatsalmost 10 years ago
From the article: <i>&quot;The messaging app Hangouts instantly processes videos, to keep them ready in the phone&#x27;s gallery.&quot;</i><p>Do you have to have the &quot;Hangouts&quot; app installed for this security vulnerability?<p>Google doesn&#x27;t seem to have learned from Microsoft&#x27;s decade of &quot;autorun&quot; problems.<p><i>It has been (0) days since the last C language buffer overflow vulnerability.</i>
评论 #9958675 未加载
Abundnce10almost 10 years ago
For TextSecure users, will this be an issue? Usually I&#x27;m prompted before I download a image&#x2F;video. Do you think I&#x27;m okay using TextSecure?
评论 #9957872 未加载
评论 #9957469 未加载
评论 #9957595 未加载
mschuster91almost 10 years ago
Why can&#x27;t Google force vendors and carriers in the Play license terms to open source their kernel and flashing technology so XDA and friends can take care of updates?<p>That would be the cheapest solution.<p>edit: added benefit, everyone is free to load on his device whatever he chooses. Google should have gone that path way earlier.
评论 #9957036 未加载
评论 #9958601 未加载
biggerfischalmost 10 years ago
Hangouts has an option under &quot;SMS&quot; to disable automatic retrieval of MMS messages. Can anyone confirm if this at least stops the instant loading of malware?
评论 #9959313 未加载
pjaalmost 10 years ago
The real problem here is that video messages expose a huge attack surface to bad actors, very little of which has been security audited.<p>Automatically parsing videos before the user even chooses to interact with them makes it even worse - although I suspect most people would play a video sent to them over MMS even if it came from an unknown contact.
评论 #9961503 未加载
stevenhalmost 10 years ago
Now would be a good time for Apple to spread word of this disaster far and wide and to offer a free iPhone to anyone who brings in an Android phone for recycling.
评论 #9958059 未加载
评论 #9958199 未加载
mikegerwitzalmost 10 years ago
There&#x27;s hype, but is there any actual information about the vulnerability anywhere? Best I was able to find was this:<p><pre><code> http:&#x2F;&#x2F;blog.zimperium.com&#x2F;the-biggest-splash-at-blackhat-and-defcon-2015&#x2F; </code></pre> Even a CVE?
评论 #9954931 未加载
评论 #9954894 未加载
评论 #9954903 未加载
评论 #9954851 未加载
forceralmost 10 years ago
I guess simplest fix for the user is to disable MMS? I don&#x27;t think its that popular feature anyway?
评论 #9955273 未加载
评论 #9954828 未加载
评论 #9954813 未加载
评论 #9954807 未加载
评论 #9956061 未加载
diminoalmost 10 years ago
Is there a CVE? I&#x27;m not sure I understand, and this article only serves to confuse. Consider this line, at the beginning:<p>&gt; In this attack, the target would not need to goof up — open an attachment or download a file that&#x27;s corrupt.<p>Is this line simply erroneous?
ck2almost 10 years ago
and tens of millions of phones will never be patched<p>this is a nightmare bug that will haunt android forever<p>I can already imagine many celebrities getting hacked through it
评论 #9956811 未加载
评论 #9956860 未加载
yodonalmost 10 years ago
What is the telecom law, if any, on text message delivery? It seems like the first network to announce &quot;we block all stage fright export messages before they hit your phone&quot; would win a huge PR coup (and they&#x27;d be able to do so much faster than trying to prep updates for every device they ever sold).
pakled_engineeralmost 10 years ago
I disabled hangouts on a device I couldn&#x27;t build from source, then got a constant alert it was trying to start again (Hangouts has unexpectedly stopped notice) so blacklisted it in startup scripts. Google gives you no option to remove it.
评论 #9955520 未加载
codeshamanalmost 10 years ago
When a vulnerability like this becomes public, I always wonder - how many people knew about it before it became public, for how long and how much has it been exploited.<p>And I also wonder how many more critical exploits are known and used by &#x27;hackers&#x27; or agencies today while we have this puffy feeling that our data&#x2F;communication is private and secure ?<p>The conclusion I can draw from this: never trust that your phone is secure. Or computer for that matter.
lsaferitealmost 10 years ago
The patches he submitted were to the kernel?<p>He says it will take a long time for those patches to make it to devices, but I question the validity of the assertion simply because Google has moved more and more into the Play framework. So, unless it is truly a kernel bug I would expect that it&#x27;s fixable in the framework ore target application.<p>Please correct me if I am mistaken though.
评论 #9956564 未加载
Zikesalmost 10 years ago
At first I thought Stagefright was the catchy name for the bug, and I expected to see a nifty logo for it as well.
评论 #9956686 未加载
kitdalmost 10 years ago
I assume this can be avoided to some extent by switching off Autodownload of MMS messages in Hangouts?
justin66almost 10 years ago
I heard the radio bit and thought it sounded reasonable. The one explanation that was missing was how this exploit fits in with those apps&#x27; permissions. The article makes it sound as though the compromised apps get root, which shouldn&#x27;t really be possible.
mSykealmost 10 years ago
I know this will soon be patched, but would it be theoretically possible to run a root exploit that would root a phone and install a superuser management app? Root your phone with just a text. That would be an interesting exploit.
评论 #9958332 未加载
评论 #9958337 未加载
AdmiralAsshatalmost 10 years ago
This is definitely a huge problem, but I only see it being a doomsday scenario <i>if</i> you&#x27;re using the default SMS app that ships with your phone (and hence cannot be updated with a patch pushed by your OEM). Assuming you&#x27;re using Hangouts or Messenger[0] (which is sorta like Hangouts without Gmail), however, as your default SMS app, you should be fine as soon as they patch it. And both of those apps are freely available to download, meaning you could always grab them once they&#x27;re patched and start using them as your default SMS app if you&#x27;re worried about it.<p>[0] <a href="https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=com.google.android.apps.messaging" rel="nofollow">https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=com.google.and...</a>
评论 #9954983 未加载
评论 #9955757 未加载
评论 #9960628 未加载
lekealmost 10 years ago
This is why my next phone will be running Unbuntu.
评论 #9959776 未加载
MBlumealmost 10 years ago
If anyone&#x27;s looking, MySMS has the relevant setting behind &quot;advanced settings&quot;
dangalmost 10 years ago
What&#x27;s the best URL for this story? It has been posted many times already.
评论 #9957426 未加载
taco_emojialmost 10 years ago
Anybody know if Textra is affected, if I turn off MMS auto-downloading?
anh79almost 10 years ago
Thanks Android. You make life much easierr :)
lop9ctrunghatqalmost 10 years ago
www.facebook.com&#x2F;thiet.bao.75
评论 #10012990 未加载
alphanumeric0almost 10 years ago
Just a_text
infinity0almost 10 years ago
It&#x27;s annoying that the media continues to incorrectly spin Android&#x27;s <i>security updates</i> problem as somehow caused by its <i>open ecosystem</i> (which itself <i>barely</i> meets the definition of open) and implying that Apple&#x27;s <i>closed system</i> is the solution.<p>GNU&#x2F;Linux distros are free open source software, and don&#x27;t suffer from these sorts of update problems. Many distros have special high-priority security update channels that are enabled by default.<p>Please, call this out if you have friends writing &#x2F; spreading such nonsense.
评论 #9956369 未加载
评论 #9954863 未加载
评论 #9955815 未加载
评论 #9954923 未加载
评论 #9955298 未加载
评论 #9954871 未加载
评论 #9960486 未加载
评论 #9955454 未加载
评论 #9954849 未加载
jbb555almost 10 years ago
&quot;The bad guy creates a short video, hides the malware inside it and texts it to your number. &quot;<p>How can you &quot;text&quot; a video? Texting uses.... text. The clue is in the name.<p>Not bothering to read the rest of the article.
评论 #9954753 未加载
评论 #9954752 未加载
评论 #9954869 未加载
评论 #9954735 未加载
评论 #9955080 未加载
pmalyninalmost 10 years ago
I only wish that there&#x27;d be a way to flash a custom ROM on an Android phone... hmmm....