• Skip to secondary menu
  • Skip to content
  • Skip to primary sidebar
  • Skip to footer

Central Toronto Real Estate - Max Seal Blog

Central Toronto Real Estate, Toronto Real Estate, Toronto Homes For Sale, Search toronto homes for sale, Max Seal, Broker, iPro Realty Ltd

  • Central Toronto Real Estate – Max Seal Blog
  • Home
    • About
  • Toronto Home Evaluation
  • Central Toronto Real Estate Blog
  • Contact Max
  • Search Toronto MLS
  • Toronto Real Estate Posts
  • FSBO Expired Listing Seller Free CMA
  • Seller
  • Buyer
  • Privacy Policy

Android rooting bug opens Nexus phones to ‘permanent device compromise’

August 14, 2021 by Central Toronto Real Estate Blog

Image 22 Android rooting bug opens Nexus phones to 'permanent device compromise”'- Screenshot - 26_03_2016

 

Millions of Android phones, including the entire line of Nexus models, are vulnerable to attacks that can execute malicious code and take control of core functions almost permanently, Google officials have warned.

The officials have already uncovered one unidentified Google Play app that attempted to exploit the vulnerability, although they said they didn’t consider the app to be doing so for malicious purposes. They are in the process of releasing a fix, but at the moment any phone that hasn’t received a security patch level of March 18 or later is vulnerable. The flaw, which allows apps to gain nearly unfettered “root” access that bypasses the entire Android security model, has its origins in an elevation of privileges vulnerability in the Linux kernel. Linux developers fixed it in April 2014 but never identified it as a security threat. For reasons that aren’t clear, Android developers failed to patch it even after the flaw received the vulnerability identifier CVE-2015-1805 in February 2015.

 

“An elevation of privilege vulnerability in the kernel could enable a local malicious application to execute arbitrary code in the kernel,” an Android security advisory published Friday stated. “This issue is rated as a critical severity due to the possibility of a local permanent device compromise and the device would possibly need to be repaired by re-flashing the operating system.”

There’s a dark side to Android root providers, even when they’re fully disclosed.

Google officials went on to say they are aware of at least one application that was available both within and outside of the official Play market place that exploited the vulnerability. Many users willingly install such rooting apps to give their phones capabilities that wouldn’t be possible otherwise. Still, as Ars reported in October, the root exploits pose a danger to the entire Android user base, even when used openly by app developers to provide added functionality. Late last year, researchers from security firm Lookout found malicious apps available in a third-party market that exploited unpatched rooting vulnerabilities to make them extremely difficult for average users to uninstall.

 

Google said its Play marketplace prohibits rooting apps. Company officials also attempt to curb the installation of such apps available in other forums through use of the verify apps feature. Friday’s advisory didn’t identify the app that was exploiting the vulnerability except to say it was publicly available, both within and outside of Play, and worked on Nexus 5 and Nexus 6 phones.

The vulnerability is present in all Android releases that use Linux kernel versions 3.4, 3.10, and 3.14. That includes all Nexus phones, as well as a large number of handsets marketed under major manufacturer brands. Android releases that use kernel versions 3.18 or higher aren’t susceptible.

 

Readers with a vulnerable phone should carefully consider the risks before knowingly installing a rooting app that exploits the flaw. They should also avoid apps available in third-party marketplaces, since they are more likely to host apps that exploit the vulnerability maliciously and without warning, and be on the lookout for updates in the coming weeks or months that patch the underlying security hole. The good news is that the flaw requires a local exploit, making remote drive-by Web attacks infeasible if not impossible.

Read the full post in ars technica

 

Please follow and like us:
RSS
Follow by Email
Facebook
fb-share-icon
Twitter
Tweet
Pinterest
Pinterest
fb-share-icon
LinkedIn
Share
Totonto Market Evaluation Online

Easy Related Posts

Low-rise homes have gained impressive 10-year result

Low-rise homes have gained impressive 10-year result

  In toronto real estate, further proof that property investment in Toronto hot market has been ...read more

Unethical agents in red-hot Toronto real estate market under the microscope

Unethical agents in red-hot Toronto real estate market under the microscope

  Who are the unscrupulous agents in Toronto's real estate market? It all depends on who you're ...read more

Toronto home prices jump in October despite new mortgage rules

Toronto home prices jump in October despite new mortgage rules

  Toronto's real estate sales clambered more than 11 per cent in October, 2016 compared with ...read more

Heat pump myths busted

Heat pump myths busted

  Ted White teaches engineering technology at the New Brunswick Community College and knows a lot about heat ...read more

Toronto housing market sets new yearly sales record in November, 2015 — and there’s still a month to go

Toronto housing market sets new yearly sales record in November, 2015 — and there’s still a month to go

  Toronto, Canada’s largest city, set a record for yearly sales as it broke new territory ...read more

Remembrance Day - November 11, 2020

Remembrance Day - November 11, 2020

Remembrance Day - November 11, 2020   On Nоvеmbеr 11, 1918 аt 11аm, thе mоѕt terrible соnflісt ...read more

Central Toronto Real Estate TRREB Released May, 2020 Resale Market Figures

Central Toronto Real Estate TRREB Released May, 2020 Resale Market Figures

  Central Toronto Real Estate TRREB Released May, 2020 Resale Market Figures   ...read more

Central Toronto Real Estate TRREB Released April, 2020 Resale Market Figures

Central Toronto Real Estate TRREB Released April, 2020 Resale Market Figures

  Central Toronto Real Estate TRREB Released April, 2020 Resale Market Figures   Tоrоntо Rеgіоnаl Rеаl Estate Bоаrd ...read more

Prices still going up in Toronto real estate market during COVID-19 crisis

Prices still going up in Toronto real estate market during COVID-19 crisis

  Prices still going up in Toronto real estate market during COVID-19 crisis   Toronto real еѕtаtе mаrkеt ...read more

Filed Under: Toronto News Posts, Toronto Seller Posts Tagged With: android rooting bug, toronto news, toronto real estate, toronto technology

Primary Sidebar

Central Toronto Real Estate – Max Seal Blog

Max Seal, Broker,
Call 647-294-1177
Email: email to Max

iPro Realty Ltd. Brokerage
1396 Don Mills Rd, #101, Bldg E, Toronto, Ontario, M3B 3N1

Totonto Market Evaluation Online

TORONTO HOME EVALUATION ONLINE

Font Resizer

  • A A A

Call, text, email Max 647-294-1177

Call Max Seal at 647-294-1177 if you are thinking to sell your upscale or average home in Central Toronto communities like Bedford Park, York Mills, Lawrence Park, Forest Hill, Davisville, Summerhill, Yorkville, Annex, Rosedale,  Leaside and Don Mills.  Please click the link for a FREE Home Evaluation. No obligation.

Search Blog Posts

Recent Posts

  • Happy New Year 2025
  • Central Toronto Real Estate TRREB Released July, 2023 Resale Market Figures
  • Central Toronto Real Estate TRREB Released April, 2023 Resale Market Figures
  • Central Toronto Real Estate TRREB Released March, 2023 Resale Market Figures
  • Central Toronto Real Estate TRREB Released February, 2023 Resale Market Figures

Recent Comments

  • Central Toronto Real Estate Blog on 7 Great Hamstring Stretches
  • lee on 7 Great Hamstring Stretches
  • Enrique Pasion on Stop Worrying Using This Simple Brain Hack
  • Joefine on Easy Weight Loss Workouts for Beginners in Toronto
  • Rumiel Daymiel on Easy Weight Loss Workouts for Beginners in Toronto

Pages

  • Central Toronto Real Estate – Max Seal Blog
  • Home
    • About
  • Toronto Home Evaluation
  • Contact Max
  • Central Toronto Real Estate Blog
  • Search Toronto MLS
  • Toronto Real Estate Posts
  • FSBO Expired Listing Seller Free CMA
  • Seller
  • Buyer
  • Privacy Policy
Totonto Market Evaluation Online

TORONTO HOME EVALUATION ONLINE

Categories

Archives

Calendar

July 2025
S M T W T F S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Dec