Android Phones Can Be Hacked Remotely By Viewing Malicious PNG Image

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12J1EDw4e=Sh1XhacpTRm91U_550heebFPfh5JrsO1mucg@mail.gmail.com>
'An innocent-looking image -- sent either via the internet or text --
could open your Android phone up to hacking. "While this certainly
doesn't apply to all images, Google discovered that a maliciously
crafted PNG image could be used to hijack a wide variety of Androids
-- those running Android Nougat (7.0), Oreo (8.0), and even the latest
Android OS Pie (9.0)," reports CSO Online. From the report:

The latest bulletin lists 42 vulnerabilities in total -- 11 of which
are rated as critical. The most severe critical flaw is in Framework;
it "could enable a remote attacker using a specially crafted PNG file
to execute arbitrary code within the context of a privileged process."
Although Google had no report of the security flaws being actively
exploited, it remains to be seen if and how long it will take before
attackers use the flaw for real-world attacks. Android owners were
urged to patch as soon as security updates becomes available. But
let's get real: Even if your Android still receives security updates,
there's no telling how long it will be (weeks or months) before
manufacturers and carriers get it together to push out the patches. '

-- source: https://yro.slashdot.org/story/19/02/11/2338245

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.