Search

Millions of Android Devices Vulnerable to Hardware Based Attack That Gives Root Access

Advertisement
Highlights
  • The Drammer attack exploits hardware components to access data
  • Researchers in Amsterdam demoed this vulnerability
  • They could completely root Samsung and OnePlus smartphones
Millions of Android Devices Vulnerable to Hardware Based Attack That Gives Root Access

Researchers of VUSec Lab at Vrije Universiteit Amsterdam have discovered a new way in which hackers can take control of millions of Android devices. In their demo, they showed how hackers could exploit data on smartphones through memory chips and other physical parts embedded inside, opening up a whole new world of vulnerabilities that wasn't thought of before. In theory, the type of attack - which exploits a new-found flaw in mobile memory - could be users on iPhones as well as other mobile devices.

The Drammer exploit is based on the Rowhammer class of attacks that target memory chips like DRAM, and has the potential to root millions of Android smartphones out there, including the ones that are running on ARM chips. This new exploit leverages a memory hardware vulnerability to surreptitiously root gain access using an app without any special permissions. The researchers claim that they have used the Drammer attack to root many LG, Motorola, Samsung, and OnePlus handsets.

Ars Technica reports that the researchers have been able to completely root Nexus 4, Nexus 5, LG G4; Moto G (2013), Moto G (2014), Samsung Galaxy S4, Samsung Galaxy S5, and the OnePlus One using the Drammer attack.

What is worse is that there is no quick fix for this exploit as well. Hardware bugs weren't even considered a possibility, and therefore no software fix was ever issued for them. "Until recently, we never even thought about hardware bugs [and] software was never written to deal with them. Now, we are using them to break your phone or tablet in a fully reliable way and without relying on any software vulnerability or esoteric feature. And there is no quick software update to patch the problem and go back to business as usual," one of the researchers, Victor van der Veen told the publication.

However, the report further notes that not all units of the above-mentioned smartphones were compromised. It largely depended on the age of the smartphone, and older the smartphone, the more vulnerable was it to the exploit - this is based on how the vulnerability works, by flipping bits on a memory module. The Rowhammer attack has been around for quite a while, but this is the first time it is seen risking smartphone data.

The researchers had even intimated Google about the vulnerability in July, for which they even received a $4,000 reward. Google is still working on a fix, and plans to release it in the November security bulletin.

Veen claims that the fix won't completely prevent hackers from exploiting, but expects it to make it very difficult. You cannot expect an OEM to stop bundling in random access memory chips and other crucial hardware components to prevent the Rowhammer exploit.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo F29 5G, Oppo F29 Pro 5G Launched in India: Price, Features
  2. Vivo Y19e With 5,500mAh Battery Launched in India: Price, Offers
  3. Infinix Note 50X 5G Battery, Charging Details Revealed; Price Range Tipped
  4. iPhone 17 Air Case Leak Hints at Pixel-Like Rear Camera Design
  5. HMD Barbie Phone With 2.8-Inch Display, Themed Accessories Launched in India
  6. Sony May Be Developing a 200-Megapixel Camera Sensor for Flagship Phones
  7. CMF Phone 2 Alleged Hands-on Renders Suggest Upgraded Rear Camera Setup
  8. Motorola Razr 60 Design, Specifications Leaked Online
  9. Huawei Pura X Foldable Phone With 6.3-Inch 16:10 Inner Display Launched
  1. Binance’s ‘Vote to List’ Feature for Community Polling on Token Listing Goes Live 
  2. xAI Launches New Grok API for Developers With Image Generation Capability
  3. Motorola Razr 60 Design, Specifications Leaked; Said to Get MediaTek Dimensity 7400X Chipset, 4,500mAh Battery
  4. Gemini Is Getting Upgraded With Audio Overview and Canvas Features
  5. HMD Barbie Phone With 2.8-Inch Main Display, Themed Accessories Launched in India: Price, Specifications
  6. Huawei Pura X Foldable Phone With 6.3-Inch 16:10 Wide Inner Screen Launched: Price, Specifications
  7. Dubai Launches Pilot Phase of Real Estate Tokenisation Project for Web3, Real Estate Collaboration
  8. Meta AI Finally Rolling Out in Europe, to Offer Limited Features at First
  9. Infinix Note 50X 5G Confirmed to Get 5,500mAh Battery Ahead of India Launch; Price Range Tipped
  10. CMF Phone 2 Alleged Hands-on Images Leak Online; Suggests Triple Rear Camera Setup
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »