Search

Rowhammer-Based 'GLitch' Exploit Emerges That Can Attack Android Devices via Browsers

Advertisement
Highlights
  • Researchers have developed an exploit based on Rowhammer technique
  • The exploit puts some Android devices at risk
  • It uses GPU to gain backdoor access
Rowhammer-Based 'GLitch' Exploit Emerges That Can Attack Android Devices via Browsers

A team of researchers has discovered a new way that lets attackers hit Android devices remotely by leveraging a four-year-old technique called Rowhammer. Called GLitch, the fresh exploit uses GPU to gain backdoor access on some Android smartphones and can be executed simply through a malicious website. It was in 2016 spotted that a Rowhammer-based exploit could root Android devices and leak their stored data. However, that previous exploit required attackers to install a malicious app on vulnerable hardware to obtain user data.

Researchers of VUSec Lab at Vrije Universiteit Amsterdam have elaborated the GLitch exploit in a paper and claimed that it takes about two minutes to attack a vulnerable Android device by pushing code from a JavaScript component available on a malicious site. The exploit notably uses standard JavaScript to compromise the device, instead of requiring any app installation or a special Web program. It essentially accesses GPU through a Rowhammer-vulnerable DRAM to take over the system. This is unlike the previous Rowhammer attacks that were majorly using CPU to exploit a system.

Thankfully, the scope of the GLitch exploit isn't as wide as the Drammer that emerged in October 2016 to attack millions of Android devices using a malicious app. The new exploit works only Mozilla's Firefox browser and can impact devices using Snapdragon 800 and Snapdragon 801 SoCs, which has the Adreno 330 GPU. Moreover, the researchers found their model successful on older devices such as the Nexus 5 that had been discontinued in the past.

In a statement to Ars Technica, Pietro Frigo, one of the four researchers in Vrije University Amsterdam Systems and Network Security Group who authored the paper, assured that on different browsers, attackers could require different techniques to build the exploit. "But, theoretically, you could exploit any target," he added.

That being said, Google in an official note to folks at Ars Technica stated that the remote vector in Chrome has been mitigated on March 13 and its team is working with other browsers to implement similar protections. Mozilla, on the other hand, disabled the vulnerable EXT_DISJOINT_TIMER_QUERY in the March release of Firefox 59 and is set to change the WebGL specifications in Firefox 60 that will be released on May 9 to make it harder for attackers to compromise devices through any Rowhammer-based exploits. Furthermore, Some anonymous Google researchers reportedly confirmed that newer Android phones come with DDR chips that have mitigations to protect the hardware from the GLitch exploit and prevent bits from flipping, which primarily gives space to Rowhammer attackers.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Rowhammer, GLitch, VUSec Lab, Android
 
Show Full Article
Please wait...
Advertisement
Popular Mobile Brands
  1. A New Greece-Set God of War Game Is Reportedly Coming This Year
  2. Motorola Edge 60 Fusion India Launch Date, Design, Key Features Revealed
  3. Vivo T4 5G India Launch Timeline, Price Range, Key Features Leaked
  4. iQOO Z10 Teased to Have a Thin Profile; to Be Available on Amazon
  5. Realme Narzo 80 Pro 5G to Launch in India Soon; Will Use This New Chipset
  6. Poco F7 India Launch Timeline, Chipset Details Tipped Online
  7. Apple's Foldable iPhone Could Launch in 2026 With iPhone 17 Air Technology
  8. These Agentic Adobe Tools Can Turn Complex Data Into Actionable Insights
  9. Here's Why Nothing Used UFS 2.2 Storage in Its New Phone 3a Series
  10. Apple Watch May Reportedly Integrate Cameras to Become an AI Wearable
  1. Indiana Jones and the Great Circle's PS5 Release Date Will Reportedly Be Announced on March 24
  2. Headphone Zone X Oriveti Blackbird In-Ear Monitor Launched in India: Price, Specifications
  3. Tamil Nadu DGP Unveils ‘Handbook for Investigations into Virtual Digital Assets’: All Details
  4. Poco F7 India Launch Timeline Leaked; Tipped to Feature Snapdragon 8s Elite Chipset
  5. Nvidia Releases Cosmos-Transfer1 AI Model That Can Be Used for Simulation-Based Training for Robots
  6. Vivo T4 5G Could Launch in India in April; Price Range, Key Features Surface Online
  7. Adobe Previews Multiple New AI Agents-Driven Enterprise Tools for Complex Data Analysis
  8. Realme Narzo 80 Pro 5G Teased to Launch in India Soon; Will Be Equipped With MediaTek Dimensity 7400 SoC
  9. Android 16 Developer Preview 3 Reportedly Enables Screen-Off Fingerprint Unlock on All Pixel Phones
  10. iQOO Z10 Teased to Measure 7.89mm in Thickness; to Be Available on Amazon
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »