Bitcoin Forum

Other => Off-topic => Topic started by: Spoetnik on August 09, 2016, 08:07:16 AM



Title: [Warning] Android "QuadRooter" Security Flaw
Post by: Spoetnik on August 09, 2016, 08:07:16 AM
900 million Android devices, including latest flagships, affected by new vulnerabilities

Quote
Four major security flaws have left around 900 million Android devices - including many of the latest flagships - vulnerable to attacks.

According to security researchers at Check Point, the vulnerabilities - which it collectively refers to as 'QuadRooter' - affect Android phones and tablets with Qualcomm chipsets. "If any one of the four vulnerabilities is exploited," Check Point's Mobile Threat Research Team said, "an attacker can trigger privilege escalations for the purpose of gaining root access to a device."

A malicious app would be able to target these security flaws without requiring special permissions to do so, potentially leaving users oblivious to an attacker gaining unrestricted access to personal data, and even sensitive corporate information. This could even include installing keylogging software on a device, as well as being able to activate the camera and microphone without the user's knowledge.

QuadRooter vulnerabilities affect a wide range of devices, including some that have been specifically marketed as offering superior security or privacy protections, such as the BlackBerry Priv, along with the Blackphone 2 and its predecessor.

http://www.neowin.net/news/900-million-android-devices-including-latest-flagships-affected-by-new-vulnerabilities

Note:
I myself do not need the patch.. i rooted my phone already  :D

So hide under your bed until it's safe to come out !

DOOOOOOOOOOOOOOOOOOOOOOM !



Title: Re: [Warning] Android "QuadRooter" Security Flaw
Post by: BitcoinNewsMagazine on August 13, 2016, 08:44:08 PM
Google just pushed out security patches for Nexus products for every vulnerability except CVE-2016-5340 which will be taken care of by early September see http://android.stackexchange.com/questions/154279/what-is-quadrooter-are-900-million-android-devices-vulnerable

You can use the Quadrooter app on the Play Store to check https://play.google.com/store/apps/details?id=com.checkpoint.quadrooter

For perspective if you are concerned see http://www.androidcentral.com/quadrooter-5-things-know-about-latest-android-security-scare

Verify Apps and SafetyNet (http://www.slashgear.com/is-google-play-scanning-my-android-phone-02377123/) should protect users until the last vulnerability is patched. Don't download apps outside of Play Store and make sure you have Verify Apps turned on. Go to settings > Google > security > turn Verify Apps on.