Article 5HGT1 Fix for critical Qualcomm chip flaw is making its way to Android devices

Fix for critical Qualcomm chip flaw is making its way to Android devices

by
Dan Goodin
from Ars Technica - All content on (#5HGT1)
phone-security-800x534.jpeg

Enlarge (credit: Getty Images)

Makers of high-end Android devices are responding to the discovery of a Qualcomm chip flaw that researchers say could be exploited to partially backdoor about a third of the world's smartphones.

The vulnerability, discovered by researchers from security firm Check Point Research, resides in Qualcomm's Mobile Station Modem, a system of chips that provides capabilities for things like voice, SMS, and high-definition recording, mostly on higher-end devices made by Google, Samsung, LG, Xiaomi, and OnePlus. Phone-makers can customize the chips so they do additional things like handle SIM unlock requests. The chips run in 31 percent of the world's smartphones, according to figures from Counterpoint Research.

The heap overflow the researchers found can be exploited by a malicious app installed on the phone, and from there the app can plant malicious code inside the MSM, Check Point researchers said in a blog post published Thursday. The nearly undetectable code might then be able to tap into some of a phone's most vital functions.

Read 9 remaining paragraphs | Comments

index?i=yGvs8lLX2lU:NPHMicaG-pk:V_sGLiPB index?i=yGvs8lLX2lU:NPHMicaG-pk:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments