Android Flaw Puts Phones At Risk Of Being Completely Wiped

By Alexandra Burlacu | Sep 30, 2012 11:05 AM EDT

Share This Story

  • Print
  • Email

Devices using Google's popular Android mobile operating system are at risk of being disabled or completely wiped clean of their data, including contacts, photos, and music.

The security flaw posing the threat was discovered several months ago, but went under the radar until now. Vulnerable devices include handsets made by Samsung, HTC, Motorola, and Sony Ericsson.

Follow us

According to computer security researcher Ravi Borgaonkar, opening a link to a Web site or a mobile application spiked with malicious code can trigger an attack capable of wiping the memory card in Android-based handsets, rendering the devices useless. Meanwhile, another code capable of performing a factory reset and erasing a user's data seems to target only Samsung phones, including the flagship Galaxy S3.

Borgaonkar said he informed Google of the vulnerability back in June. A fix rolled out quickly and quietly, leaving smartphone owners basically unaware that a problem existed or how they could fix it.

Launched in 2008, the Android OS currently dominates the smartphone market. According to market research firm IDC, nearly 198 million Android smartphones were sold in the first six months of the year, and roughly 243 million Android phones were sold in 2011.

Vulnerable versions of Android include Gingerbread, Ice Cream Sandwich, and the latest Jelly Bean, while the Honeycomb version designed for tablets still needs to be tested, noted Borgaonkar.

Samsung, the biggest Android phone maker, said only early production models of its flagship galaxy S3 were affected, and a software update has already been issued for that model. The company added that it is currently conducting an internal review to check if other devices are affected and determine what action is needed, if any. Meanwhile, Samsung is advising users to check for software updates through the "Settings: About device: Software update" menu.

Borgaonkar explained that the bug works by exploiting phone functions that allow them to dial a phone number directly from a Web browser. A person can create a Web site or an app with codes, instructing the phones linking to those numbers to automatically execute commands such as a full factory reset.

A phone's memory card, i.e. a subscriber identity module, or SIM, can be destroyed remotely in the same manner, added Borgaonkar.

"Vulnerability in Android can be exploited to kill the SIM card permanently by clicking a single click," he noted. "After the successful attack, the end user has to go to the mobile network operator and buy a new SIM card." 

 

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Jolla SailfishFormer Nokia Team Jolla, Announces First Sailfish Powered Smartphone For Asia
Motorola XFon May Hit Verizon, Sprint Later This Year
More BlackBerry Devices On The Way, Says Sprint
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Transform It Into Galaxy S4 (To Some Extent)
Tablet / Laptop / PC
Lenovo ThinkPad HelixLenovo ThinkPad Helix Hybrid Tablet-Ultrabook Now Available Starting At $1679
Samsung Galaxy Tab 3 Leaks In Benchmarks With Intel Inside
Samsung Galaxy S4, Galaxy Note 8.0 Top Consumer Reports Rankings
Samsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Gadgets
Intel ISEF 2013 WinnersRecharge Your Phone In 20 Seconds With This Revolutionary Device
Ouya Will Be At E3 2013, But Not Where You Think
Next Microsoft Xbox To Sport Dashboard UI Update And Tile Changes
Google Media Streamer Hits FCC To Replace Nexus Q
OS / Software
Jolla SailfishFormer Nokia Team Jolla, Announces First Sailfish Powered Smartphone For Asia
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Transform It Into Galaxy S4 (To Some Extent)
iOS 7 To Come With Flickr, Vimeo Integration
Samsung Galaxy S4 'Google Edition' Will Be Available In U.S. Only?
Internet / Social Media
FaceTimeAT&T Promises Cellular Video Calls, Mobile Video Chat For All Customers
Flickr Boasts 'Spectacular' Redesign, Offers A Whopping 1TB Of FREE Storage
Download 40 GB In A Second: Researchers Set Up World's Fastest Wi-Fi Network In Germany
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
What's App
Nokia Xpress Now Web AppNokia Xpress Now Web App Announced For Asha Devices
Samsung Galaxy S4 App Contest Boasts $800,000 Total Prizes For Talented Devs
Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included

DON'T MISS

Galaxy S3 Jelly Bean Update
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Transform It Into Galaxy S4 (To Some Extent)
The Android 4.2.2 Jelly Bean firmware for the Samsung Galaxy S3 has been leaked and many users of
Motorola USB Drivers .ini File
Motorola XFon May Hit Verizon, Sprint Later This Year
An .ini file pulled from Motorola USB drives shows a Motorola XT1060 handset, i.e. the rumroed
Jolla Sailfish
Former Nokia Team Jolla, Announces First Sailfish Powered Smartphone For Asia
Nokia's former MeeGo team is gearing up to take the smartphone world by storm with a new operating
Sprint 4G LTE
More BlackBerry Devices On The Way, Says Sprint
If you were left impressed with the major releases from BlackBerry earlier this year viz. BlackBerry
Lenovo ThinkPad Helix
Lenovo ThinkPad Helix Hybrid Tablet-Ultrabook Now Available Starting At $1679
The new Lenovo ThinkPad Helix is the company's first hybrid ultrabook with a detachable Windows 8
Intel ISEF 2013 Winners
Recharge Your Phone In 20 Seconds With This Revolutionary Device
A California teen has developed a tiny gizmo that could charge a phone in just 20 to 30 seconds,

Intel Inside
Samsung Galaxy Tab 3 Leaks In Benchmarks With Intel Inside
The Samsung Galaxy Tab 3 appeared in two different benchmark test results, suggesting the
Samsung Galaxy Note 3 GT-N7200 Leaked Benchmark
Samsung Galaxy Note 3 Spotted In Benchmarks, Suggesting Imminent Launch
The Samsung Galaxy Note 3 has just popped up in some benchmark test results with the model number
iOS 7 Concept Design
iOS 7 To Come With Flickr, Vimeo Integration
The move of integrating Flickr and Vimeo in the upcoming iOS 7 looks really impressive and the iOS
Galaxy S4 World Tour in China
Samsung Galaxy S4, Galaxy Note 8.0 Top Consumer Reports Rankings
The verdict is out: the Samsung Galaxy S4 is hotter than the LG Optimus G, while the Samsung Galaxy
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics