Android Bugs Leave Every Smartphone And Tablet Vulnerable To Privilege Escalation

Standard

It is easy to miss factors when you’re overwhelmed with details. After looking around we did find something that might be of use. You could read it now.

Pileup, which is short for privilege escalation through updating , increases the permissions offered to malicious apps once Android is updated, without informing the user. “Every few months, an update is released, which causes replacement and addition of tens of thousands of files on a live system. Each of the new apps being installed needs to be carefully configured to set its attributes within its own sandboxes and its privileges in the system, without accidentally damaging existing apps and the user data they keep,” the researchers wrote. “This complicates the program logic for installing such mobile updates, making it susceptible to security-critical flaws.” “Through the app running on a lower version of Android, the adversary can strategically claim a set of carefully selected privileges or attributes only available on the higher OS version,” the researchers wrote. The problem, to put it simply, is that for the sake of convienience the Android user interface doesn’t pop up any prompts pointing out the new permissions, but instead assigns them automatically in the background without giving the user any say in the matter. The researchers claim to have discovered six different Pileup vulnerabilitieswithin the Android Package Management Service (PMS), and have confirmed that these vulnerabilities are present in all Android Open Source Project versions, along with more than 3,500 customized versions of Android developed by handset OEMs and carriers. In total, the researchers claim that this leaves more than a billion Android devices vulnerable to a Pileup attack. “A third-party package attribute or property, which bears the name of its system counterpart, can be elevated to a system one during the updating shuffle-up where all apps are installed or reinstalled, and all system configurations are reset,” the researcher wrote.
Explore the original version including any type of supplementary pictures or video clips by stopping by http://www.zdnet.com/android-bugs-leave-every-smartphone-and-tablet-vulnerable-to-privilege-escalation-7000027589/

Leave a comment