Stagefright: major Android security flaw affects millions
Hackers can use the vulnerability to read text messages, look at photos and spy on Android owners through their phone's camera
Android users have been warned that a major security flaw, nicknamed Stagefright, allows hackers to access smartphones simply by sending a malicious text message.
The flaw is thought to affect the vast majority of Android users and means hackers can read messages, look at private photos or even spy on users through a smartphone's camera and microphone.
According to Joshua Drake, the researcher who found the flaw, hackers can exploit the vulnerability to take control of almost any Android phone simply by sending an infected video via MMS (multimedia messaging service).
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.
Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
Users cannot even defend themselves by filtering out suspicious messages because the way Google pre-processes videos to make them quicker to view means that the bug will infect a phone "before the sound that you've received a message has even occurred," Drake said in an interview with NPR.
So far, there is no known solution for the problem, but security analysts say that Google is likely to be working on a fix that can be distributed as soon as possible, The Guardian reports.
Chris Wysopal, the chief information security officer for mobile security service Veracode said that "it will be very interesting to see how Google responds to this. They'll have to drive the patch quickly and in a manner that impacts every affected device at the same time. Waiting for handset manufacturers or carriers to issue a patch would be problematic since it could take a month or more.
"This would leave a big window for an attacker to reverse engineer the first patch issued by whichever party to create an exploit that would impact any device. We're likely to see Google force down a tool that addresses the vulnerability for everyone."
Fortune's Robert Hackett advises that the only thing users can do to try to protect themselves is to change the settings for apps that use MMS, such as Messages and Hangouts. " Un-click 'automatically retrieve MMS messages'," Hacket says. "In the meantime, consider using Snapchat or WhatsApp to swap clips, GIFs, and whatnot."
Video: 950 million Android phone vulnerable
[[{"type":"media","view_mode":"content_original","fid":"83498","attributes":{"class":"media-image"}}]]
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
-
'Without mandatory testing, bird flu will continue circulating at farms across the country'
Instant Opinion Opinion, comment and editorials of the day
By Justin Klawans, The Week US Published
-
Thirteen missing after Red Sea tourist boat sinks
Speed Read The vessel sank near the Egyptian coastal town of Marsa Alam
By Arion McNicoll, The Week UK Published
-
Khan supporters converge on Islamabad
Speed Read Protesters clashing with Pakistani authorities are demanding the release of jailed former prime minister Imran Khan
By Rafi Schwartz, The Week US Published
-
DOJ seeks breakup of Google, Chrome
Speed Read The Justice Department aims to force Google to sell off Chrome and make other changes to rectify its illegal search monopoly
By Peter Weber, The Week US Published
-
Google Maps gets an AI upgrade to compete with Apple
Under the Radar The Google-owned Waze, a navigation app, will be getting similar upgrades
By Justin Klawans, The Week US Published
-
Is ChatGPT's new search engine OpenAI's Google 'killer'?
Talking Point There's a new AI-backed search engine in town. But can it stand up to Google's decades-long hold on internet searches?
By Theara Coleman, The Week US Published
-
'Stunningly lifelike' AI podcasts are here
Under the Radar Users are amazed – and creators unnerved – by Google tool that generates human conversation from text in moments
By Abby Wilson Published
-
Will the Google antitrust ruling shake up the internet?
Today's Big Question And what does that mean for users?
By Joel Mathis, The Week US Published
-
Wall Street tumbles on poor tech results
Speed Read US markets had their worst day since 2022 as Tesla and AI stocks dropped
By Arion McNicoll, The Week UK Published
-
Why is the tech industry up in arms about Google's search algorithm leak?
Today's Big Question A leak of about 2,500 documents shed light on how Google's search engine operates, and not everyone is happy
By Justin Klawans, The Week US Published
-
How AI is going to change the Google search experience
Talking Points Summaries are the new links
By Joel Mathis, The Week US Published