Search

Linux Vulnerability Leaves 1.4 Billion Android Devices Open to Security Threat: Report

Advertisement
Highlights
  • The security flaw reportedly exists on 80 percent of Android devices
  • The flaw was revealed USENIX Security 2016 conference recently
  • Lookout has suggested use of VPN to avoid being spied upon
Linux Vulnerability Leaves 1.4 Billion Android Devices Open to Security Threat: Report

Just when you might be wrapping your head around that QuadRooter saga, researchers from mobile security firm Lookout have suggested that a newly discovered Linux flaw essentially "allows an attacker to remotely spy on people who are using unencrypted traffic or degrade encrypted connections."

The Linux kernel vulnerability, which was revealed recently in TCP at the USENIX Security 2016 conference, was introduced in version 3.6 of the Linux OS kernel (released in 2012) and exists in all Android smartphones running version 4.4 KitKat or later, as pointed out in the security firm's blog post.

As Lookout points out, that's 80 percent of Android devices according to Google's latest distribution figures, or roughly 1.4 billion devices, based on Statista's figures.

The vulnerability means that attackers would be able to detect communications over a TCP connection, and if unencrypted, even insert malicious code into that traffic. "While a man in the middle attack is not required here, the attacker still needs to know a source and destination IP address to successfully execute the attack," Lookout said in its blog. Lookout has suggested that Android users should consider using VPN while browsing and also encrypt the communications to prevent them from being spied on.

As the exploit is relatively hard to execute, Lookout has assigned medium severity rating to the flaw but does clarify that the risk of "targeted attacks" is there. The underlying Linux OS kernel vulnerability is classified as CVE-2016-5696, and has been patched.

The security firm has said that even though the patch for the Linux kernel was created on July 11, with the latest developer preview of Android 7.0 Nougat, the kernel doesn't seem to be patched against this particular flaw.

Speaking to Ars Technica, a Google representative said the company was aware of the vulnerability and was "taking the appropriate actions". The representative went on to say that the Android security team rates the risk "moderate," as opposed to "high" or "critical" for many of the vulnerabilities it patches

Note, this is not the first Linux kernel vulnerability that has affected Android in the recent past, with Google in March admitting vulnerabilities in Android code based on Linux kernel versions 3.4, 3.10, and 3.14. The company had made available a patch to OEMs, and worked to remove the vulnerabilities from its own Nexus devices.

Last week, a set of vulnerabilities dubbed as QuadRooter surfaced and was claimed to affect roughly 900 million Android devices. According to researchers if any one of the vulnerabilities is exploited, an attacker can gain root access to the affected device.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's 20th iPhone Anniversary May Witness Several New Product Launches
  2. Moto G86 Power 5G Design, Colour Options, Key Features Surface Online
  3. Kindle Paperwhite (12th Gen) Review: The E-reader Champ Is Back
  4. Xiaomi Civi 5 Pro Tipped to Launch in May; Key Features Surface Online
  5. Alcatel V3 Ultra Retail Box Image Reveals Design, Specifications
  6. iOS 19 Will Sync Public Wi-Fi Networks Across All Your Apple Devices
  7. Samsung Might Use a Different Chip for Galaxy Z Flip 7 Than Galaxy Z Fold 7
  1. Samsung Galaxy Buds Core Allegedly Sighted on BIS Site Ahead of Launch in India
  2. Samsung’s Galaxy Z Flip 7 Said to Get Exynos 2500 SoC, Galaxy Z Flip FE Might Not Use Exynos Chipset
  3. Xiaomi Civi 5 Pro With Snapdragon 8s Gen 4 SoC Tipped to Launch in May; Key Features Surface Online
  4. Apple’s 20th iPhone Anniversary Roadmap Includes Plans for Foldable iPhone, Smart Glasses and More
  5. Crypto Price Today: Bitcoin Hovers Over $103,000 Price Point, Ether Breaches $2,500 Mark After Months 
  6. OpenAI Negotiates with Microsoft for New Funding, Future IPO: Report
  7. Researchers Unveil LegoGPT AI Model That Can Build Physically Stable Design of Lego Structures
  8. Moto G86 Power 5G Design, Colour Options, Key Specifications Surface Online
  9. Alcatel V3 Ultra Moniker Confirmed, Retail Box Image Reveals Design, Specifications
  10. Virtua Fighter 5 REVO Announced For PS5, Xbox Series S/X and Nintendo Switch 2
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »