Specialists from Cambridge University presented new way of tracing Android – and и iOS- devices…
According to the researchers, the problem affects at least 10 popular Android devices, including Google Pixel 2, Huawei Nexus 6P and Samsung Galaxy S8 Plus.
Read also: Trend Micro employee sold customers’ data to scammers
Vulnerabilities were found in the interface used to communicate with the firmware of the radio module, which allows the phone’s modem to communicate with the cellular network – to make phone calls or connect to the Internet. This software is usually isolated from other applications and often sold with a blacklist of commands to prevent the launch of unimportant commands.
According to the researchers, some phones inadvertently provide Bluetooth and USB accessories, such as headphones and headsets, with access to the firmware of the radio module. Using vulnerable accessories, an attacker can execute commands on Android smartphones connected to them.
“The impact of these attacks ranges from disclosing user confidential information to a complete denial of service”, – say the researchers.
The firmware of the radio module is capable of receiving special AT-commands that control the cellular functions of the device. As the researchers found, commands can be manipulated.
During testing, the researchers found 14 commands that can be used to trick vulnerable Android phones, steal sensitive data and manage calls.
As the researchers explained, low-cost Bluetooth connectors or malicious USB charging stations can be used for attacks. Thus, an attacker can manipulate a smartphone using a computer (if the accessory is reachable via the Internet) or through a connection to a Bluetooth device (for this, the attacker must be in close proximity to it).
“If the smartphone is connected to a headset or any other Bluetooth device, the attacker can first exploit vulnerabilities in the Bluetooth protocol, and then inject malicious AT-commands”, – note the researchers.
Chernars.com is a domain that tries to force you into subscribing to its browser notifications…
Eclipse-adblocker.pro is a site that tries to trick you into clik to its browser notifications…
Initiateadvancedcompletelythe-file.top is a site that tries to force you into subscribing to its browser notifications…
Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…
Prizestash.com is a site that tries to trick you into subscribing to its browser notifications…
Verifiedbreaking.com is a domain that tries to force you into subscribing to its browser notifications…