5 years, 5 months ago

146 New Vulnerabilities All Come Preinstalled on Android Phones

When you buy an Android smartphone, it’s rarely pure Android. The vulnerabilities Kryptowire turned up, in research funded by the Department of Homeland Security, encompass everything from unauthorized audio recording to command execution to the ability to modify system properties and wireless settings. “We wanted to understand how easy it is for someone to be able to penetrate the device without the user downloading an application,” says Kryptowire CEO Angelos Stavrou. The tool looks for “unsafe states,” as Stavrou puts it, that would allow an application to take a screenshot or record audio or create a network connection when it shouldn’t. Many of the vulnerabilities Kryptowire found enable apps to do things like change settings without your knowledge or consent.

Wired

Discover Related