Skip to main content

Android’s April security patch fixes a major vulnerability to hijacks over WiFi

There's always some new security flaw that needs patching. It's been revealed that some Broadcom chips allow rogue Wi-Fi signals to execute code of attacker's choosing. Google has fixed this in the April security update but it can take a while before devices receive it and some devices won't get the update at all.


The Broadcom chip is used in both iOS and Android devices. Apple already patched the vulnerability, but Google is still in the process of releasing the fix. The lack of security protections in the Broadcom chip made it a prime target. It's a pretty severe vulnerability, so make sure you update your device as soon as possible.

A broad array of Android phones are vulnerable to attacks that use booby-trapped Wi-Fi signals to achieve full device takeover, a researcher has demonstrated.

The vulnerability resides in a widely used Wi-Fi chipset manufactured by Broadcom and used in both iOS and Android devices. Apple patched the vulnerability with Monday's release of iOS 10.3.1. "An attacker within range may be able to execute arbitrary code on the Wi-Fi chip," Apple's accompanying advisory warned. In a highly detailed blog post published Tuesday, the Google Project Zero researcher who discovered the flaw said it allowed the execution of malicious code on a fully updated 6P "by Wi-Fi proximity alone, requiring no user interaction."

Google is in the process of releasing an update in its April security bulletin. The fix is available only to a select number of device models, and even then it can take two weeks or more to be available as an over-the-air update to those who are eligible. Company representatives didn't respond to an e-mail seeking comment for this post.

The proof-of-concept exploit developed by Project Zero researcher Gal Beniamini uses Wi-Fi frames that contain irregular values. The values, in turn, cause the firmware running on Broadcom's wireless system-on-chip to overflow its stack. By using the frames to target timers responsible for carrying out regularly occurring events such as performing scans for adjacent networks, Beniamini managed to overwrite specific regions of device memory with arbitrary shellcode. Beniamini's code does nothing more than write a benign value to a specific memory address. Attackers could obviously exploit the same series of flaws to surreptitiously execute malicious code on vulnerable devices within range of a rogue access point.

Basic mitigations missing

Besides the specific stack overflow bugs exploited by the proof-of-concept attack, Beniamini said a lack of security protections built into many software and hardware platforms made the Broadcom chipset a prime target.

"We've seen that while the firmware implementation on the Wi-Fi SoC is incredibly complex, it still lags behind in terms of security," he wrote. "Specifically, it lacks all basic exploit mitigations—including stack cookies, safe unlinking and access permission protection (by means of [a memory protection unit.])"

The Broadcom chipset contains an MPU, but the researcher found that it's implemented in a way that effectively makes all memory readable, writeable, and executable. "This saves us some hassle," he wrote. "We can conveniently execute our code directly from the heap." He said that Broadcom has informed him that newer versions of the chipset implement the MPU more effectively and also add unspecified additional security mechanisms.

Given the severity of the vulnerability, people with affected devices should install a patch as soon as it's available. For those with vulnerable iPhones, that's easy enough. As is all too often the case for Android users, there's no easy way to get a fix immediately, if at all. That's because Google continues to stagger the release of its monthly patch bundle for the minority of devices that are eligible to receive it.

At the moment, it's not clear if there are effective workarounds available for vulnerable devices. Turning off Wi-Fi is one possibility, but as revealed in recent research into an unrelated Wi-Fi-related weakness involving Android phones, devices often relay Wi-Fi frames even when Wi-Fi is turned off. This post will be updated if word of a better workaround emerges.



via Blogger http://ift.tt/2p8R943

Comments

Popular posts from this blog

AlpineQuest GPS Hiking 2.0.4

AlpineQuest GPS Hiking Android   AlpineQuest is the complete solution for all outdoor activities and sports, including hiking, running, trailing, hunting, sailing, geocaching, off-road navigation and much more. You can access and store locally a large range of on-line topographic maps, which will remain available even while being out of cell coverage. AlpineQuest also supports on-board file based maps, like MemoryMap(c) maps. By using the GPS and the magnetic sensor of your device (with compass display), getting lost is part of the past: you are localized in real-time on the map, which can also be oriented to match where you are looking at. Save and retrieve landmarks, share them with your friends. Track your path, get advanced statistics and interactive graphics. You won't have anymore questions about what you can accomplish. By staying fully operational out of cell coverage (as often in mountain or abroad), AlpineQuest assists you in all your desires of deep wild...

Official Xposed Framework for Android Nougat is Here

As the Android ecosystem has matured over the years, fewer and fewer users find reasons why they should root their device. There's a growing trend of users choosing to stay on the stock firmware, either because they find the experience satisfactory or don't want to play a  cat-and-mouse game with Google's SafetyNet API . But if you asked a user back in early 2016 why they rooted their phones, perhaps the number one reason that was given was so they could  install the Xposed Framework . It's been  over a year since Android 7.0 Nougat  was first released, but the long wait is finally over:  official Xposed Framework for Android Nougat is finally available. Throughout the past year, XDA Senior Recognized Developer  rovo89 , the lead developer of the Xposed Framework, has provided  several   updates  on the progress of Xposed Framework for Android Nougat. For some, the  wait has been tolerable  mostly due to the sheer number of additional functionality that the Xpos...

How well does the LG G6 perform in a durability torture test? [VIDEO]

The LG G6 is the first LG flagship in years to feature a nearly all-glass build (remember the LG Optimus G?). There's only a very thin sheet of glass covering the back of the LG G6 and because of this, you may be wondering about the phone's durability. Since you would never want to test something like this on your own device, Zack from JerryRigEverything is back again without another one of his famous torture tests. He basically puts the LG G6 through hell, scratching and abusing the phone with a variety of tools before he gets to the real reason we're all here: the bend test. Surprisingly enough, the LG G6 passes with flying colors, providing no catastrophic failures or even much bending at all using with Zack using the full force of his hands. It's a testament to how far LG has come, showing that they're perfectly capable of manufacturing phones with solid build quality. For more on the LG G6, don't forget to check out our unboxing and ...