Friday, May 6, 2016

FireEye Finds Surveillance Bug in Android

Image: FireEye - Malicious code using the CVE-2016-2060 exploit
Security firm Fire Eye published a blog post on Thursday detailing a new exploit that could allow attackers to access data such as text messages on Android phones. Listed as "CVE-2016-2060," the vulnerability was patched by Google in May, but some phones remain susceptible because many phone carriers and manufacturers restrict Google's monthly updates.

"This vulnerability allows a seemingly benign application to access sensitive user data including SMS and call history and the ability to perform potentially sensitive actions such as changing system settings or disabling the lock screen," wrote the FireEye researchers.

Because many manufacturers use proprietary versions of Android, many users may never see a fix for this exploit on their phones.

No comments:

Post a Comment