Qualcomm has released an update to fix a vulnerability in its Snapdragon chips that exposes about a third of Android smartphones worldwide. The flaw was discovered by a group of researchers from security firm Check Point and disclosed on Thursday (06/05).
According to researchers, the vulnerability affected the MSM (Mobile Station Modem), a chip system that provides capabilities for sending SMS messages and recording in high definition. This set can be found in devices with Snapdragon chips, from companies such as Samsung, Xiaomi, LG, OnePlus and many others. Just to give you an idea of the scope of this vulnerability, Qualcomm processors are present in 31% of smartphones on the planet, according to Counterpoint Research data.
The flaw was installed in the system through an app that implanted malicious code within the MSM. The hidden key then invaded vital functions on the cell phone. “An attacker uses this vulnerability to inject malicious code into the Android modem, giving access to the user’s call and text message history, as well as the ability to listen to conversations,” he says. the publication released today. “A hacker also exploits the vulnerability to unlock the device’s SIM, bypassing restrictions imposed by carriers.”
In an official statement, the Qualcomm thanks the company for the discovery and says it provided updates for the vulnerability as early as December 2020. “We encourage edge users to update their devices as patches become available,” the text says. It is worth mentioning that Check Point had already done so a warning last year, drawing attention to more than 400 vulnerabilities present in Snapdragon processors.
Delay in correction
Even with Qualcomm’s update, Check Point spokesperson Ekram Ahmed explains that the fixes for the vulnerability will take some time to take effect. Precisely because, even though the American company has disclosed the bug to all customers using the chip, it is still not clear which Android devices have been fixed. “In our experience, implementing these fixes takes time, so some of the phones may still be subject to the threat,” explains Ahmed. “Therefore, we decided not to share all the technical details, as this would give hackers a roadmap to orchestrate the exploit.”
The vulnerability has been tracked as CVE-2020-11292. Check Point made the discovery through a process known as “fuzzing,” which exposes the chip’s system to anomalous inputs to track down bugs in the firmware. In this post, Check Point explains the problem in detail.
Through which channels you reach those people, classic and out of the box. Ars Technica
Image: Monoar_CGI_Artist/Pixabay/CC