Skip to main content

Android’s April security patch fixes a major vulnerability to hijacks over WiFi

There's always some new security flaw that needs patching. It's been revealed that some Broadcom chips allow rogue Wi-Fi signals to execute code of attacker's choosing. Google has fixed this in the April security update but it can take a while before devices receive it and some devices won't get the update at all.


The Broadcom chip is used in both iOS and Android devices. Apple already patched the vulnerability, but Google is still in the process of releasing the fix. The lack of security protections in the Broadcom chip made it a prime target. It's a pretty severe vulnerability, so make sure you update your device as soon as possible.

A broad array of Android phones are vulnerable to attacks that use booby-trapped Wi-Fi signals to achieve full device takeover, a researcher has demonstrated.
The vulnerability resides in a widely used Wi-Fi chipset manufactured by Broadcom and used in both iOS and Android devices. Apple patched the vulnerability with Monday's release of iOS 10.3.1. "An attacker within range may be able to execute arbitrary code on the Wi-Fi chip," Apple's accompanying advisory warned. In a highly detailed blog post published Tuesday, the Google Project Zero researcher who discovered the flaw said it allowed the execution of malicious code on a fully updated 6P "by Wi-Fi proximity alone, requiring no user interaction."
Google is in the process of releasing an update in its April security bulletin. The fix is available only to a select number of device models, and even then it can take two weeks or more to be available as an over-the-air update to those who are eligible. Company representatives didn't respond to an e-mail seeking comment for this post.
The proof-of-concept exploit developed by Project Zero researcher Gal Beniamini uses Wi-Fi frames that contain irregular values. The values, in turn, cause the firmware running on Broadcom's wireless system-on-chip to overflow its stack. By using the frames to target timers responsible for carrying out regularly occurring events such as performing scans for adjacent networks, Beniamini managed to overwrite specific regions of device memory with arbitrary shellcode. Beniamini's code does nothing more than write a benign value to a specific memory address. Attackers could obviously exploit the same series of flaws to surreptitiously execute malicious code on vulnerable devices within range of a rogue access point.

Basic mitigations missing

Besides the specific stack overflow bugs exploited by the proof-of-concept attack, Beniamini said a lack of security protections built into many software and hardware platforms made the Broadcom chipset a prime target.
"We’ve seen that while the firmware implementation on the Wi-Fi SoC is incredibly complex, it still lags behind in terms of security," he wrote. "Specifically, it lacks all basic exploit mitigations—including stack cookies, safe unlinking and access permission protection (by means of [a memory protection unit.])"
The Broadcom chipset contains an MPU, but the researcher found that it's implemented in a way that effectively makes all memory readable, writeable, and executable. "This saves us some hassle," he wrote. "We can conveniently execute our code directly from the heap." He said that Broadcom has informed him that newer versions of the chipset implement the MPU more effectively and also add unspecified additional security mechanisms.
Given the severity of the vulnerability, people with affected devices should install a patch as soon as it's available. For those with vulnerable iPhones, that's easy enough. As is all too often the case for Android users, there's no easy way to get a fix immediately, if at all. That's because Google continues to stagger the release of its monthly patch bundle for the minority of devices that are eligible to receive it.
At the moment, it's not clear if there are effective workarounds available for vulnerable devices. Turning off Wi-Fi is one possibility, but as revealed in recent research into an unrelated Wi-Fi-related weakness involving Android phones, devices often relay Wi-Fi frames even when Wi-Fi is turned off. This post will be updated if word of a better workaround emerges.

Comments

Popular posts from this blog

Chrome Browser – Google 57.0.2987.126 Apk for Android

Sync Across Devices– seamlessly access and open tabs and bookmarks from your laptop, phone or tablet Save Data– reduce mobile data usage by up to 50% while browsing Faster Browsing– choose from search results that instantly appear as you type and quickly access previously visited pages Voice Search– use the magic of Google voice search to find answers on-the-go without typing Translate– easily read webpages in any language Intuitive Gestures– open as many tabs as your heart desires and quickly flip through them by swiping from side to side on the toolbar Privacy– use Incognito mode to browse without saving your history Download for android  +4.1,+5.0,+6.0,+7.0 click here From Google Play store here What's New in Chrome 56: • Quickly use emails, addresses, and phone numbers in web pages by tapping on them • Easily access downloaded files and web pages from the new tab page • Long press article suggestions on the new tab page to download them • Bug fixes and performa...

Possible Asus ZenFone Max Pro M2 (6GB RAM) render shows off a notched display

In the Indian budget and mid-range market, Xiaomi smartphones reign supreme. Xiaomi’s Redmi Note series, soon to be joined by the  Redmi Note 6 Pro in India , are hard to beat in the price conscious Indian market. But the Asus ZenFone Max Pro M1 has been a serious contender for best mid-range smartphone in India when it was launched  earlier this year . With a Qualcomm Snapdragon 636, up to 6GB RAM/64GB storage, a 5.99-inch 1080×2160 LCD, dual 13+5MP rear cameras, 5,000mAh battery, and near stock  Android 8.1  Oreo, the ZenFone Max Pro M1 seems like the perfect smartphone for an Indian XDA user on a budget. We’ve heard rumors that Asus is gearing up to launch the ZenFone Max Pro M2, and now the device has appeared online with what may be the first press render showing off its notched display. A few days ago, notable leaked Roland Quandt from WinFuture tweeted some  possible specifications  for the upcoming Asus ZenFone Max Pro M2. A...

Memedroid Pro Funny memes apk

Memedroid Pro Funny memes 5.2.18 Apk for Android Memedroid Pro Funny memes Brace Yourself! Great Memes Are Coming! You deserve a good laugh: discover one of the greatest online communities of meme lovers and humor fans all over the world and start having fun right now 🙂 – It's the best meme app to brighten up your day and you can even create memes by yourself! On top of all our funny memes, Memedroid also grants you access to many hilarious GIFs – Just click to play! With Memedroid everything is laughable – From amusing popular memes such as "bad luck Brian" and the "skeptical third world kid" to political satire all the way through celebrity memes – anything goes as long as it is funny! You can even make your own memes with Memedroid's memes maker! Spice-up your day to day routine with the best funny life memes, fit for any occasion! Start the bustle of the week with a hilarious Monday meme, get out of bed smiling with a new and amusing ...