Write For Us

Many Android devices ship with firmware vulnerabilities, researchers find


© Illustration by Alex Castro / The Verge

By Shoshana Wodinsky, The Verge

[post_ads]Asus, Essential, LG, and ZTE have all vowed to patch security flaws found by mobile security firm Kryptowire, according to Wired. The firm’s research was meant to point out that some security meltdowns stem from code written by phone companies to modify Android.

Researchers found bugs in the firmware of 10 separate devices carried across the major American carriers, according Wired, which saw an early version of Kryptowire’s report. The security lapses could lead to everything from letting an attacker lock someone out of their device, to getting control over their microphone and more — though most of the attacks that the researchers detailed required users to download some sort of malicious app before they could take advantage of the holes present in the firmware. Their research, funded by the Department of Homeland Security, is being presented today at the Black Hat USA security conference.

According to Kryptowire, these vulnerabilities stem from Android’s open nature, which allows third-parties to tweak the code and modify the interference or create completely different versions of Android. However, as the researchers found out, this open-style system can also lead to gaps in the phones’ security. Wired says the research looks at these flaws as a problem endemic to Android.

“A lot of the people in the supply chain want to be able to add their own applications, customize, add their own cod,” Kryptowire CEO Angelos Stavrou told Wired. “That increases the attack surface, and increases the probability of software error.”

One particularly bad example was found in the Asus Zenfone V Live smartphone. According to Wired, Kryptowire found enough holes in its code to expose users to a complete takeover of their device — screenshots and video recordings could be taken of their screen, and someone could, theoretically, read and changing their text messages. Asus said it is “aware of the recent security concerns” and that it is “working diligently and swiftly to resolve them” with a patch.
Essential, LG, and ZTE all responded to Wired with statements saying they had fixed some or all of the problems identified by Kryptowire after being alerted by the firm. Whether those patches have been rolled out to all users is less clear, however, as only AT&T confirmed it had deployed any of these updates. And as the researchers point out, this update process is, itself, broken for many, with updates often taking months to put together and make their way to users.


Note: If you think this story need more information or correction, feel free to comment below your opinion and reaction.
Like & Follow to Stay Updated ...


AI,3,Amazon,1,Apple,5,Emoji,1,Facebook,17,Games,35,Google,7,Instagram,6,Science,205,Security,4,Social Media,24,Tech,242,Technology,1396,Tesla,5,Twitter,4,
Technology - U.S. Daily News: Many Android devices ship with firmware vulnerabilities, researchers find
Many Android devices ship with firmware vulnerabilities, researchers find
Technology - U.S. Daily News
Loaded All Posts Not found any posts VIEW ALL Read More Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy