When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

Home / News / New Android vulnerabilities could expose nearly all devices to hacks

New Android vulnerabilities could expose nearly all devices to hacks

"Stagefright" issues found within code are deemed "worst discovered to date," but Google is aware

Many of us view MMS messages throughout each and every week, but if you have an Android phone and the message comes from a malicious source, it could well make your device vulnerable to hackers.

That’s according to Zimperium Mobile Security, whose researchers discovered a host of vulnerabilities within Stagefright, the media playback engine found within Android 2.2 and higher. Google surely now regrets that name, given the problems that Stagefright could introduce.

Zimperium says that the malicious code can be executed simply by receiving the MMS message, so anyone with your phone number could send it – and there’s no indication that anything has changed (as seen in Zimperium’s example flow below). You don’t even need to open the MMS: the preview notification alone does the trick, which makes this exploit much more devious than most.

It may even be possible for someone to send a message and then delete it remotely without you even seeing it. Once the trojan horse is on your phone or tablet, the sender could have remote access to your device and files, and could use that access to steal data or destroy the phone’s contents. The problem could theoretically affect upwards of 95% of Android devices, or about 950 million of them worldwide.

Yes, it all sounds quite terrible, but we’re not trying to spook Android owners – and neither is Zimperium. Like a responsible firm should, the company reported the issues to Google in April, and Google implemented patches for manufacturers and carriers to release. That means that some phones may already be secured – like the Blackphone.

But many Android partners haven’t yet issued those patches to consumers – alas, the typically slow Android update cycle – which means there’s plenty of uncertainty over which phones are vulnerable and how you can avoid potential issues. The news is fresh, so we won’t have a lot of those answers just yet; stay tuned, however, and we’ll share anything more we hear about updates and potential recovery options if you’re affected.

[Source: Zimperium Labs via Wired UK]

Profile image of Andrew Hayward Andrew Hayward Freelance Writer

About

Andrew writes features, news stories, reviews, and other pieces, often when the UK home team is off-duty or asleep. I'm based in Chicago with my lovely wife, amazing son, and silly cats, and my writing about games, gadgets, esports, apps, and plenty more has appeared in more than 75 publications since 2006.

Areas of expertise

Video games, gadgets, apps, smart home

Enable referrer and click cookie to search for eefc48a8bf715c1b ad9bf81e74a9d264 [] 2.7.22