Google and Samsung Fix Android Spying Flaw. Other Makers May Still Be Vulnerable

Peter Reutemann <[email protected]> Wed, 20 Nov 2019 12:14:43 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JwC+JFcavP+DsHbdRTJzoP=OfOhcgEpAvvDb19QnL7qg@mail.gmail.com>
'Until recently, weaknesses in Android camera apps from Google and
Samsung made it possible for rogue apps to record video and audio and
take images and then upload them to an attacker-controlled server --
without any permissions to do so. Camera apps from other manufacturers
may still be susceptible. From a report:

The weakness, which was discovered by researchers from security firm
Checkmarx, represented a potential privacy risk to high-value targets,
such as those preyed upon by nation-sponsored spies. Google carefully
designed its Android operating system to bar apps from accessing
cameras and microphones without explicit permission from end users. An
investigation published Tuesday showed it was trivial to bypass those
restrictions. The investigation found that an app needed no
permissions at all to cause the camera to shoot pictures and record
video and audio. To upload the images and video -- or any other image
and video stored on the phone -- to an attacker-controlled server, an
app needed only permission to access storage, which is among one of
the most commonly given usage rights.

The weakness, which is tracked as CVE-2019-2234, also allowed would-be
attackers to track the physical location of the device, assuming GPS
data was embedded into images or videos. Google closed the
eavesdropping hole in its Pixel line of devices with a camera update
that became available in July. Checkmarx said Samsung has also fixed
the vulnerability, although it wasn't clear when that happened.
Checkmarx said Google has indicated that Android phones from other
manufacturers may also be vulnerable. The specific makers and models
haven't been disclosed.'

-- source: https://tech.slashdot.org/story/19/11/19/1737219

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz