ADVERTISEMENT

New bug lets hackers infect Androids via multimedia files

In practical terms, this means that an attacker can remotely execute code on a victim’s device by sending them a malicious MP3 or MP4 file.

Android Marshmallow is going to be Google's next OS and it will be taking over from Android Lollipop

Back in July, a bug in Android’s media playback system called Stagefright, which only needed a specially crafted text message to the victim’s phone in order to remotely execute code, left about a billion devices vulnerable to hackers.

Although Google promptly issued a parch for that particular vulnerability, the security research company that initially found the original bug, Zimperium, has found two new vulnerabilities in Stagefright, which could enable hackers to take over an Android device by sending the victim a specially crafted multimedia file.

“All Android devices without the yet-to-be-released patch contain this latent issue,” said a researcher at Zimperium zLabs, Joshua Drake.

In practical terms, this means that an attacker can remotely execute code on a victim’s device by sending them a malicious MP3 or MP4 file. The bad part is that the victim doesn’t even have to open the file.

ADVERTISEMENT

"The vulnerability lies in the processing of metadata within the files, so merely previewing the song or video would trigger the issue," wrote Zimperium in a blog post.

Google has acknowledged the issue, but a patch is still not available yet. Even when Google does release a patch, it could take some time for Android phone manufacturers to implement it.

The best thing for users to do right now is to avoid downloading or opening multimedia files and links with unknown sources.

JOIN OUR PULSE COMMUNITY!

Unblock notifications in browser settings.
ADVERTISEMENT

Eyewitness? Submit your stories now via social or:

Email: eyewitness@pulse.ng

Recommended articles

UNN to reduce unemployment among Nigerian graduates through mentoring

UNN to reduce unemployment among Nigerian graduates through mentoring

AGF calls for strong internal controls to curb financial mismanagement

AGF calls for strong internal controls to curb financial mismanagement

Tariff has been hiked with no improvement - Abuja residents decry power outage

Tariff has been hiked with no improvement - Abuja residents decry power outage

Emefiele's trial adjourned to June 24, key witness cross-examined

Emefiele's trial adjourned to June 24, key witness cross-examined

Former ECOWAS Court VP slams EFCC chairman's handling of Yahaya Bello case

Former ECOWAS Court VP slams EFCC chairman's handling of Yahaya Bello case

Let’s drill 200k boreholes across the country  —  Obi begs wealthy Nigerians

Let’s drill 200k boreholes across the country  —  Obi begs wealthy Nigerians

Ondo 2024: Ex-governor's brother emerges gubernatorial candidate

Ondo 2024: Ex-governor's brother emerges gubernatorial candidate

UK varsity rolls out tuition, travel-free scholarship for Nigerian students

UK varsity rolls out tuition, travel-free scholarship for Nigerian students

President Biden signs law to potentially ban TikTok if not sold

President Biden signs law to potentially ban TikTok if not sold

ADVERTISEMENT
ADVERTISEMENT