Thursday, January 30, 2025
HomeMobile AttacksNokia 9 PureView Fingerprint Sensor Is Fooled by Chewing Gum

Nokia 9 PureView Fingerprint Sensor Is Fooled by Chewing Gum

Published on

SIEM as a Service

Follow Us on Google News

The brand new Nokia flagship with five camera modules looks pretty promising but has several significant weaknesses. Recently, it shocked the world with dangerous security flaw related to its onscreen fingerprint sensor that is tricked by non-registered patterns of other fingers and even various items such as coins or gloves.

Users noticed the first issue right after the launch. Then, Nokia’s scanner had too low sensitivity and didn’t recognize the owners’ fingerprints often.

HMD Global responded to this problem with a patch dated by 19 April. The update improved the scanner’s sensitivity and really helped people to interact with their smartphones. Too much.

As for now, the PureView has an extremely responsive sensor that recognizes not only fingerprints of owners but also other prints and material objects, e.g. chewing gum packs, coins, gloves, etc.

The problem was spotted by Twitter user Decoded Pixel. He posted a video where his Nokia 9 is unlocked with two different fingers and chewing gum

Why This Happened?

The most recent update for Android 9 Pie 4.22 includes the patch from HMD Global. Most likely, engineers didn’t improve the recognition algorithm but simply lowered the sensitivity threshold so PureView now accepts prints with a quite low original match. Phone owners mention that they can unlock the gadget with almost any touch, including random taps and fingers wrapped in cloth. Developers still didn’t react to multiple complaints.

As usual, people also joke about the issue. Reddit users mention that this is a new Nokia feature that will be available for extra money – the Gum ID. Still, we shouldn’t forget about the real danger of such flaws as frauds can easily get access to stolen phones due to identification errors. The next OTA update should fix the sensor so it’s better to disable this feature now and use traditional PIN codes or graphic patterns. As well, you can order dedicated software development Ukraine here to get extra security layers for your applications.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

CISA Released Secure Mobile Communication Best Practices – 2025

The Cybersecurity and Infrastructure Security Agency (CISA) has released new best practice guidance to...

Ghost Tap Attack, Hackers Stolen Credit Card Linked To Google Pay Or Apple Pay

Threat actors are exploiting a new cash-out tactic called "Ghost Tap" to siphon funds...

HookBot Malware Use Overlay Attacks Impersonate As Popular Brands To Steal Data

The HookBot malware family employs overlay attacks to trick users into revealing sensitive information...