Computer scientist uncovers Android SMS phishing vulnerability
Network World - A researcher at North Carolina State University has uncovered a vulnerability that could be exploited to send deceptive text messages from some Android devices, as part of a phishing scheme.
MORE ON ANDROID: Hottest Android news and rumors for the week ending Nov. 2
Particularly worrisome is the fact that the vulnerability doesn't need any elevated app permissions in order to function, said NCSU computer science professor Xuxian Jiang.
"The vulnerability allows a running [untrusted] app on the phone to fake an incoming SMS text message with arbitrary content, including the text message itself as well as the 'sending' phone number, which can be your friend in the contact list or simply your trusted banks," Jiang said in an email to Network World.
The flaw is apparently present in the Android Open-Source Project, and some versions of the software ranging from 1.6 (Donut) to 4.1 (Jelly Bean) are vulnerable. Jiang said that his team has been able to exploit it on the Samsung's Galaxy Nexus, Nexus S and Galaxy S III, HTC's One X and Inspire, and the Xiaomi MI-One.
Jiang praised Google for reacting quickly, confirming the presence of the vulnerability within two days of receiving the team's report. In the email, he expressed hope that a rapid patch would be forthcoming.
Jiang did not provide full technical details of the flaw, citing responsible disclosure issues, although he did describe the vulnerability as difficult to detect but easy to exploit, once found.
Jiang has been at the forefront of the discovery of several other Android security flaws, including, in June, a rootkit attack that might have allowed malicious software to be concealed on an affected device. He is the founder of the Android Malware Genome Project, an academic investigation of security threats affecting the platform.
Email Jon Gold at jgold@nww.com and follow him on Twitter at @NWWJonGold.
Read more about software in Network World's Software section.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Red Hat JBoss Fuse Compared with Oracle Service Bus Competitive Brief Read this paper to learn how to start more projects, deploy technology more pervasively within the enterprise, and apply more of your budget...
- Red Hat JBoss BRMS Best Practices Guide Learn the technical best practices for development with Red Hat JBoss Enterprise BRMS. Following the best practices outlined in these guides will result...
- Red Hat JBoss Enterprise Application Platform and IBM WebSphere Application Server Network Deployment Edition This competitive brief outlines the differences in the economies of the competing application platforms, the implementation of the JEE specification, open standards support...
- Red Hat JBoss Enterprise Application Platform and Oracle WebLogic Server Edition Competitive Brief This competitive brief outlines the differences in the economies of the competing application platforms, the implementation of the JEE specification, open standards support...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
On-Demand Webcast: 7 Reasons to Choose VoIP - Thinking about a new phone system for your business?
Be sure to watch this informative webcast. Steve Strauss, small business columnist for USA... - Live Webcast
Unified Communications 101 - Learn more!
- Boost Performance & Profitability with Better Planning & Mobile Reporting This session will discuss how Ashurst, a top-tier legal service provider for private and public sector clients worldwide, was able to effectively manage...
- Apps and BlackBerry 10 - Tips for IT Learn how to easily create, deploy and manage both off-the-shelf and custom apps, improving productivity and efficiency for employees by mobilizing apps, processes... All Applications White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!