/?pid=easily-exploitable-certifi-gate-bug-opens-android-devices-to-hijacking-16185

Updated:03:35 AM EST Feb 26


this is ggmania.com subsite Easily exploitable Certifi-gate bug opens Android devices to hijacking - TechAmok

Easily exploitable Certifi-gate bug opens Android devices to hijacking - [security]
06:38 AM EDT - Aug,10 2015 - post a comment

Check Point's mobile security research team discovered a vulnerability in Android that affects phones, tablets and devices made by major manufacturers including LG, Samsung, HTC and ZTE. The team disclosed its findings during a briefing session at Black Hat USA 2015. "Certifi-gate" is a vulnerability - a set of vulnerabilities, actually - in the architecture of mobile Remote Support Tools (mRSTs) used by virtually every Android device manufacturer and network service provider. The vulnerability allows applications to gain illegitimate privileged access rights, which are typically used by remote support applications that are either pre-installed or personally installed on Android devices.

Attackers can exploit Certifi-gate to gain unrestricted device access, allowing them to steal personal data, track device locations, turn on microphones to record conversations, and more. Hundreds of millions of Android devices, including those running Lollipop OS, can be hijacked. A study by the researchers revealed the existence of multiple instances of a fundamental flaw within the Android customisation chain that leave millions of devices (and users) vulnerable to attack. The researchers say the vulnerabilities are "very easily exploited."

The root causes of these vulnerabilities include hash collisions, IPC abuse and certificate forging which allow an attacker to grant their malware complete control of a victim's device. Android offers no way to revoke the certificates that provide the privileged permissions. Left unpatched, and with no reasonable workaround, devices are exposed right out of the box. OEMs also cannot revoke the valid signed vulnerable components, making unpatched versions valid for installation on devices. These vulnerabilities allow an attacker to take advantage of unsecure apps certified by OEMs and carriers to gain unrestricted access to any device, including screen scraping, key logging, private information exfiltration, back door app installation, and more

Short overview of recent news articles

I built the most BORING PC possible... and here is why it's (Feb,26 2026 )

Micron Blasts GDDR7 as Gaming Bottleneck While Nvidia's RTX 50 (Feb,26 2026 )

UK Tightens Grip on Streaming Giants: Age Verification Now Mandatory (Feb,26 2026 )

Samsung Previews New AI Features Ahead of Flagship Phone Launch (Feb,25 2026 )

China's DeepSeek Bars Nvidia and AMD from New AI Model, Boosts (Feb,25 2026 )

Avast Impersonation Scam: Fake Site Tricks Users into Handing Over (Feb,25 2026 )

Microsoft Pulls the Plug: Windows Server 2016 and 2016-Era Windows (Feb,25 2026 )

I Scrapped 13 MACHINES to Prove a Point: STOP BUYING These Brands! (Feb,25 2026 )

How Stealthy was the 7zip Malware and how to spot it? (Feb,25 2026 )

Microsoft Drops Fresh Non-Security Boost for Windows 11 24H2 and (Feb,25 2026 )

Game-Changer: ASML's 1kW EUV Upgrade Promises 50% Chip Production (Feb,24 2026 )

This Outstanding Cooling Technology Might Have No Future (Feb,24 2026 )

AMD Strix Halo 395 vs Intel Panther Lake - Real Benchmarks (Feb,24 2026 )

Anthropic published a blog post saying Claude can modernize COBOL (Feb,24 2026 )

WhatsApp Goes Beyond 2FA: Extra Password Layer Makes Accounts Nearly (Feb,24 2026 )

Google Chrome Gets February 23 Security Boost with 3 High Fixes (Feb,24 2026 )

Stargate Stalls: OpenAI's $500B Dream Hits Roadblocks as $14B 2026 (Feb,23 2026 )

Google Crushes Cyber Threats: Blocks 1.75 Million Bad Apps and Bans (Feb,23 2026 )

Bitcoin Miner Bitdeer Sells Everything: Treasury Hits Zero in AI (Feb,22 2026 )

HW News - More Valve RAM Shortages, Tariffs Ruling, AI Causes PS6 (Feb,22 2026 )

Microsoft's Deep Integration of Copilot in Windows 11 Raises (Feb,22 2026 )

Elon Musk Confirms X Money Now Live in Internal Beta for Employees, (Feb,22 2026 )

Scream (1996) Flashback Review (Feb,22 2026 )

PayPal Confirms Major Breach: SSNs, Emails, and More Exposed from (Feb,22 2026 )

Does Freezing Help Delidding? 9850X3D Delid & Overclocking Test (Feb,22 2026 )

Microsoft is phasing out the custom primary password feature in its (Feb,22 2026 )

Everyone is Buying the Wrong Dash Cam! (2026) (Feb,21 2026 )

Big Brother on Discord: Leaked Code Shows Age Verification Runs You (Feb,20 2026 )

OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened (Feb,19 2026 )

Google Adds Satellite SOS to its Affordable Pixel Phone (Feb,19 2026 )

Phison CEO Warns: AI-Driven NAND and DRAM Shortage Could Bankrupt (Feb,19 2026 )

NVIDIA CEO hypes up GTC 2026, promises to unveil a chip that will (Feb,19 2026 )

Microsoft is uploading your confidential emails to Copilot for (Feb,19 2026 )

Anthropic Releases Claude Sonnet 4.6 with Improved Coding, Computer (Feb,18 2026 )

Apple Eyeing A Partnership With Chinese Memory Makers YMTC And CXMT (Feb,17 2026 )

This $60,000 TV was IRRESISTIBLE (Feb,17 2026 )

Keenadu Android Backdoor Infects Firmware, Spreads via Google Play (Feb,17 2026 )

Discord's ID Check Nightmare Sparks Massive Exodus to TeamSpeak (Feb,17 2026 )

Amazing Robot Performance at the 2026 Spring Festival Gala (Feb,17 2026 )

Apple brings video podcasts and other improvements in iOS 26.4 beta (Feb,16 2026 )

Dutch Defence Secretary Boldly Claims F-35 Software Could Be (Feb,16 2026 )

Samsung shows off Galaxy S26 Ultra privacy display (Feb,16 2026 )

60 Million Passwords Exposed? ETH Zurich Shatters 'Unbreakable' (Feb,16 2026 )

Apple MacBook with iPhone chip launches next month (Feb,15 2026 )

Discord's Disturbing Ties to Global Surveillance | ID Verification, (Feb,15 2026 )

20 Mind-Blowing Tech Gadgets You MUST See in 2026! (Feb,15 2026 )

Western Digital's HDD production capacity for 2026 is fully sold (Feb,15 2026 )

Google Releases First Beta Version of Android 17 (Feb,14 2026 )

The Audiophile Gaming Headset - HIFIMAN x ROG Kithara (Feb,14 2026 )

7zip Malware: Beware 7zip.com (Feb,14 2026 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs