Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

AP Photo/Jeff Chiu

Android phones have a serious flaw that could allow hackers in with one text

And as many as 950 million Android phones could be affected by it.

ANDROID PHONES MAY be vulnerable to a security flaw which could allow attackers into your phone through a single text.

According to Zimperium zLabs, the flaw doesn’t even require the user to open the text message to take effect.

The weakness is found in Stagefright, a media playback tool in Android, and as many as 950 million Android phones could be affected, according to Forbes.

The issue lies with Google Hangouts, which acts as the default SMS messenger for your phone. Since it automatically processes video received so it’s ready in your phone’s gallery, the malware enters your phone without requiring you to open up the text.

All an attacker needs to do is create a short video, hide the malware inside and text it to your number. There have been no instances of this flaw being exploited as of yet (if you can’t make out the image below, click here).

Cat1-1024x534 How the security flaw works. Zimperium Zimperium

Joshua Drake, a security researcher with Zimperium, told NPR he shared his findings with Google in April and May, and sent over patches to help fix the bugs. Google applied the patches to its internal code branches within 48 hours.

However, the length of time it takes for an upgrade to Android to reach all phones takes a long time as it’s not in Google’s hands. Drake estimates that as few as 20% of Android phones will get fixed, with an optimistic number reaching 50%. Part of the reason behind that estimate is that devices that are 18 months or older are unlikely to receive an update.

It’s better to assume your phone hasn’t been patched yet so to avoid this, it’s best to avoid using Hangouts entirely and change to a different SMS app like your phone’s default messenger app. Even then, you should be careful about the type of text messages you view, especially if it’s from an unfamiliar number.

If you have to rely on Hangouts, you can disable auto-retrieve MMS by going into settings > SMS and finding the option under the advanced submenu and untick it.

If you’re one of the few people who has an Android phone with version 2.2 or older, you’re safe.

This isn’t the first time a text message created problems for smartphones. Back in May, Apple’s iOS system had a problem which let you crash an iPhone by sending it a specific text.

Read: Is Twitter really taking down stolen jokes because of copyright infringement? >

Read: This monitor wants to wirelessly charge your phone while you work >

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Author
Quinton O'Reilly
View 20 comments
Close
20 Comments
    Submit a report
    Please help us understand how this comment violates our community guidelines.
    Thank you for the feedback
    Your feedback has been sent to our team for review.
    JournalTv
    News in 60 seconds