Computer scientist uncovers Android SMS phishing vulnerability
Network World - A researcher at North Carolina State University has uncovered a vulnerability that could be exploited to send deceptive text messages from some Android devices, as part of a phishing scheme.
MORE ON ANDROID: Hottest Android news and rumors for the week ending Nov. 2
Particularly worrisome is the fact that the vulnerability doesn't need any elevated app permissions in order to function, said NCSU computer science professor Xuxian Jiang.
"The vulnerability allows a running [untrusted] app on the phone to fake an incoming SMS text message with arbitrary content, including the text message itself as well as the 'sending' phone number, which can be your friend in the contact list or simply your trusted banks," Jiang said in an email to Network World.
The flaw is apparently present in the Android Open-Source Project, and some versions of the software ranging from 1.6 (Donut) to 4.1 (Jelly Bean) are vulnerable. Jiang said that his team has been able to exploit it on the Samsung's Galaxy Nexus, Nexus S and Galaxy S III, HTC's One X and Inspire, and the Xiaomi MI-One.
Jiang praised Google for reacting quickly, confirming the presence of the vulnerability within two days of receiving the team's report. In the email, he expressed hope that a rapid patch would be forthcoming.
Jiang did not provide full technical details of the flaw, citing responsible disclosure issues, although he did describe the vulnerability as difficult to detect but easy to exploit, once found.
Jiang has been at the forefront of the discovery of several other Android security flaws, including, in June, a rootkit attack that might have allowed malicious software to be concealed on an affected device. He is the founder of the Android Malware Genome Project, an academic investigation of security threats affecting the platform.
Email Jon Gold at email@example.com and follow him on Twitter at @NWWJonGold.
Read more about software in Network World's Software section.
- The Principles of the Business Data Lake The Business Data Lake is a new approach to information management, analytics and reporting that better matches the culture of business and better...
- Start with a Data Lake. End with Business Value. Pivotal Big Data Suite enables companies to store all data, accelerate processing and most importantly increase the amount of data being analyzed and...
- Store Everything. Analyze Anything, Build the Right Thing. The value of Information has increased, so has the business's thirst for more information.
- How Four Citrix Customers Solved the Enterprise Mobility Challenge Managing mobile devices, data and all types of apps-Windows, datacenter, web and native mobile- through a single solution.
- Transform Your IT Service Management Watch this webinar, to learn how EasyVista can increase IT productivity & efficiency and deliver streamlined & integrated IT Service & Asset Mgmt.
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Applications White Papers | Webcasts