Millions Of Android Phones Are Vulnerable To Israeli Surveillance Dealer Attack
upstart writes:
Submitted via IRC for carny
Millions Of Android Phones Are Vulnerable To Israeli Surveillance Dea...
Google issued an alert overnight about a fresh vulnerability affecting hundreds of millions of Android phones, including its own Pixel 1 and 2 devices. According to Google security researcher Maddie Stone, the weakness is actively being used against targets of the Israeli spyware dealer NSO Group.
If you own any of the following phones, your device likely remains vulnerable today as patches are not yet available: the Google Pixel 1 and 2, Huawei P20. Xiaomi Redmi 5A, Xiaomi Redmi Note 5. Xiaomi A1, Moto Z3, Oreo LG phones and the Samsung S7, S8, S9 models. Those are some of the most popular Android phones in existence today. Huawei has shipped over 16 million P20 smartphones around the world, according to the Chinese company's figures from the end of 2018. (A source told Forbes after publication that the number of affected devices is likely much higher, as those were the only ones that Google had been able to test).
[...] The problem was defined by Stone as a kernel privilege escalation bug, which means it provided a way for a hacker who'd already found a way onto the device to get deeper access, right into the heart of the Android operating system. Getting control of the kernel allows a hacker to do almost whatever they like on the phone, grabbing much of the data within. Whoever was exploiting the vulnerability would have likely used other bugs, combining them in what's known as an "exploit chain" to completely own an Android device remotely. That is, after all, what NSO trades in; it's built a reputation for being able to remotely target and take over smartphones, but its reported sales of this technology to Mexico and the U.A.E. has put it at the center of a storm over privacy and surveillance.
from the all-phones-are-surveillance-devices dept.
Read more of this story at SoylentNews.