Cyber Attack | Data Breach

Published on July 27th, 2019 📆 | 3036 Views ⚑

0

Android Media Framework Flaw Could Get Phones Hacked By Videos


iSpeech

Most smartphone users love to watch innocent videos of babies, pets, and other cute moments. Interestingly, the hackers also like to share videos with you. However, they also wish to have your phone’s access in return. Reportedly, hackers could exploit an Android Media Framework flaw to gain access to your phone simply by playing a malicious video.

Android Media Framework Flaw

A researcher has recently disclosed the exploit for an Android Media Framework flaw. As revealed, a critical remote code execution vulnerability (CVE-2019-2107) affected the Android systems. Exploiting the flaw could let an attacker take control of the device.

To exploit the flaw, an attacker could merely send a maliciously crafted video to the target device. A German developer, Marcin Kozlowski, has shared a proof-of-concept on GitHub demonstrating the attack. As stated by Kozlowski,

With CVE-2019-2107 the decoder/codec runs under mediacodec user and with properly “crafted” video (with tiles enabled – ps_pps->i1_tiles_enabled_flag) you can possibly do RCE.

However, the attack may not work if the video reaches the victim’s device via an IM app like WhatsApp. Nor the video would exploit the flaw if reached through Facebook Messenger or Twitter, or even played via YouTube. It is because these services generally re-encode media files or compress videos. This, in turn, garbles the malicious code embedded within the video.

New Android Devices Vulnerable

Fortunately, Google has already patched the vulnerability. It rolled-out the fix with the Android July updates released earlier this month.

Google deemed this vulnerability as ‘critical’ that affected Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9. Describing the flaw in Android Media Framework, Google stated,





The most severe of these issues is a critical security vulnerability in Media framework that could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process.

While the fix is already out, users must ensure to keep their devices updated to avoid any such attacks since the exploit is also now publicly available. Additionally one should make sure to avoid playing videos from untrusted sources to stay protected.

Let us know your thoughts in the comments.

The following two tabs change content below.

Avatar
Abeerah has been a passionate blogger for several years with a particular interest towards science and technology. She is crazy to know everything about the latest tech developments. Knowing and writing about cybersecurity, hacking, and spying has always enchanted her. When she is not writing, what else can be a better pastime than web surfing and staying updated about the tech world! Reach out to me at: [email protected]
Avatar

Source link

Tagged with:



Comments are closed.