TechnoclinicTechnoclinic
  • Home
  • APPS
  • CAMERAS
    • PRINTERS
  • GAMING
    • LAPTOPS
  • HDTV
  • NEWS
  • PHONES
    • TABLETS
  • REVIEWS
  • SOFTWARE
  • Contact Us!
Search
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Reading: New Stagefright Vulnerability Found, Millions of Android Devices Affected: Report
Share
Sign In
Aa
TechnoclinicTechnoclinic
Aa
Search
  • Home
  • APPS
  • CAMERAS
    • PRINTERS
  • GAMING
    • LAPTOPS
  • HDTV
  • NEWS
  • PHONES
    • TABLETS
  • REVIEWS
  • SOFTWARE
  • Contact Us!
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technoclinic > PHONES > New Stagefright Vulnerability Found, Millions of Android Devices Affected: Report
PHONES

New Stagefright Vulnerability Found, Millions of Android Devices Affected: Report

srijita
Last updated: 2016/03/17 at 11:43 AM
srijita
Share
SHARE

New Stagefright Vulnerability Found, Millions of Android Devices Affected: Report

New Stagefright Vulnerability Found, Millions of Android Devices Affected: Report

Security researchers have once again discovered a flaw in Android’s Stagefright mediaserver component. In a demonstration, the researchers were able to remotely hack a phone with Stagefright-based exploit. Their finding underscores a vulnerability in millions of Android devices that could be triggered when they are made to visit a specially-crafted webpage.

Israel-based research firm Northbit published a research paper this week in which it claims to have found a “proper” exploit dubbed Metaphor, using a new vulnerability in the Stagefright. The firm’s researchers said that they were remotely able to hack a Nexus 5, and have successfully replicated the exploit on a LG G3, Samsung Galaxy S5, and HTC One. According to them, devices running Android 5.0 Lollipop or v5.1, that account for roughly 36 percent of 1.4 billion active devices are vulnerable.

In the paper, the researchers have described a three-step process to hijack an Android device. A user is first made to visit a specially-crafted webpage that hosts a video file capable of crashing the mediaserver software on the target handset. The video file resets the mediaserver software and waits for it to restart. After which, a JavaScript on the webpage sends information about the device to the attacker’s server, which then generates another video file, sends it to the device, and fetches more information such as the internal state of the device. After this, another video file is sent to the victim’s device, and executes a payload of malware, and begins spying.

The exploit attacks the CVE-2015-3864 bug in a “fast, reliable and stealthy” way, says researchers, that bypasses ASLR (address space layout randomization). As you can imagine, for security attackers to be successful in hijacking the device, they need to perform a cascade of operations.

A bug in Stagefright, an Android multimedia library, was first found in July. Google had patched the bug, though security researchers had found flaws in the patch. Stagefright 2.0 was detected in October. It was estimated to affect almost all Android devices on the planet.

[“source-ndtv”]

TAGGED: Affected, Android, Devices, found, Millions, New, of, Report, Stagefright, Vulnerability

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
srijita March 17, 2016
Share this Article
Facebook Twitter Copy Link Print
Share
Previous Article EU Regulators Want More Info on Apple’s Irish Tax Deal
Next Article Apple Co-Founder Steve Wozniak on Cook, FBI, Tesla, and His Life

Latest News

How to Clean Your Flat-Screen TV The Right Way
HDTV
AI and Content Management: How Organizations Can Prepare for the Future
SOFTWARE
What is Application Software: Function and Features of Application
APPS
Case Study: Nissan and Teads’ Immersive Concept Car Campaign Transformed Scrolls into Stories
NEWS
Review of Hootsuite: Advantages, Drawbacks, Features, and Other Options
REVIEWS
From Idea to Launch: The Software Development Journey
SOFTWARE

Most Viewed Posts

  • Choosing the Right Tablet for Blogging and Writing On the Go (1,075)
  • What You Need to Know About Smartphones vs. Tablet use of the Mobile Internet (1,019)
  • How To Start A Review Blog and Get Free Review Products (1,018)
  • How to Start a Product Review Blog (Templates & Examples) (1,015)
  • App Annie now tracks 5,000 Android apps in China: Report (993)

© 2023 TechnoClinic Network. TechnoClinic Company. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?