Thursday, December 19, 2024
HomePoCAndroid Ecosystem Contains Several Hidden Patch Gaps that Can be Exploited by...

Android Ecosystem Contains Several Hidden Patch Gaps that Can be Exploited by Hackers

Published on

SIEM as a Service

The Android operating system is one of the most widely used platforms with 2 billion active users at the same time it facing a lot of security issues that need frequent fixes and release the patch for the users is one of the main processes in Android Ecosystem.

Android Phones are receiving monthly security patches and it needs to be implemented by specific vendors for their respective mobile models.

But most of the Android manufacturing vendor are regularly forget to fix some of the patches including Critical and High severity rate flaws that lead to underlying risks, eventually, it will be exploited by the cybercriminals.

- Advertisement - SIEM as a Service

In this case, Google can release an important update for software related flaws without any specific vendors interaction but in-terms of drivers and system libraries, there should be respective manufacturers involvement.

Some of the phones still contain several hidden Patch gaps included multiple times with different firmware’s releases.

missed_patches by vendor

In this list shows the missing Critical and High severity patches before the claimed patch date (Few: 5-9; Many: 10-49; Lots: 50+).

This research was based on how many patching mistakes are made in this complex
The Android ecosystem that means how many patches go missing.

Android Ecosystem Patching is Really Very Hard

The nature of Android makes patching is really much more difficult it has gone through a lot of complex challenges.

Patches are handed down a long chain of typicality four parties before reaching the user including OS vendors, chipset vendors, Phone vendors, telecom vendors.

Patches are released more frequently by OS vendors but sometimes other vendors are failed to implement within the specific time.

Android Exploitation is Really Super Hard

Android security system contains several security layers and performing remote hack a phone is typically very hard since the attacker has to handle with multiple vulnerabilities to reach the point where he can take the control over the vulnerable mobile.

According to Security Research Labs, a few missing patches are usually not enough for a hacker to remotely compromise an Android device.

“That leaves state-sponsored and other persistent hackers, who usually operate stealthily. These well-funded hackers would typically resort to “zero-day” vulnerabilities but may also rely on known bugs to develop effective exploit chains. “

In this case, single defense layer can withstand large hacking incentives for very long, prompting “defense in depth” approaches with multiple security layers.

Details of this research were presented at the HITB conference on April 13, 2018, in Amsterdam: Announcement and slides

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Europol Details on How Cyber Criminals Exploit legal businesses for their Economy

Europol has published a groundbreaking report titled "Leveraging Legitimacy: How the EU’s Most Threatening Criminal...

CISA Proposes National Cyber Incident Response Plan

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a proposed update to the...

Iranian Hackers Launched A Massive Attack to Exploit Global ICS Infrastructure

In a joint cybersecurity advisory, the FBI, CISA, NSA, and partner agencies from Canada,...

Next.js Vulnerability Let Attackers Bypass Authentication

A high-severity vulnerability has been discovered in the popular web framework, Next.js, which allows...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Deloitte Denies Breach, Claims Only Single System Affected

Ransomware group Brain Cipher claimed to have breached Deloitte UK and threatened to publish...

Poison Ivy APT Launches Continuous Cyber Attack on Defense, Gov, Tech & Edu Sectors

Researchers uncovered the resurgence of APT-C-01, also known as the Poison Ivy group, an...

Hackers Can Secretly Access ThinkPad Webcams by Disabling LED Indicator Light

In a presentation at the POC 2024 conference, cybersecurity expert Andrey Konovalov revealed a...