Nokia 9 PureView Fingerprint Sensor Is Fooled by Chewing Gum

The brand new Nokia flagship with five camera modules looks pretty promising but has several significant weaknesses. Recently, it shocked the world with dangerous security flaw related to its onscreen fingerprint sensor that is tricked by non-registered patterns of other fingers and even various items such as coins or gloves.

Users noticed the first issue right after the launch. Then, Nokia’s scanner had too low sensitivity and didn’t recognize the owners’ fingerprints often.

HMD Global responded to this problem with a patch dated by 19 April. The update improved the scanner’s sensitivity and really helped people to interact with their smartphones. Too much.

As for now, the PureView has an extremely responsive sensor that recognizes not only fingerprints of owners but also other prints and material objects, e.g. chewing gum packs, coins, gloves, etc.

The problem was spotted by Twitter user Decoded Pixel. He posted a video where his Nokia 9 is unlocked with two different fingers and chewing gum

Why This Happened?

The most recent update for Android 9 Pie 4.22 includes the patch from HMD Global. Most likely, engineers didn’t improve the recognition algorithm but simply lowered the sensitivity threshold so PureView now accepts prints with a quite low original match. Phone owners mention that they can unlock the gadget with almost any touch, including random taps and fingers wrapped in cloth. Developers still didn’t react to multiple complaints.

As usual, people also joke about the issue. Reddit users mention that this is a new Nokia feature that will be available for extra money – the Gum ID. Still, we shouldn’t forget about the real danger of such flaws as frauds can easily get access to stolen phones due to identification errors. The next OTA update should fix the sensor so it’s better to disable this feature now and use traditional PIN codes or graphic patterns. As well, you can order dedicated software development Ukraine here to get extra security layers for your applications.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Google Guide! How to Detect Browser Data Theft Using Windows Event Logs

In the ever-evolving cybersecurity landscape, Google is continually striving to protect user data from malicious actors. In a recent blog…

2 hours ago

Millions of Malicious “Imageless” Docker Hub Repositories Drop Malware

In a startling revelation, nearly 20% of Docker Hub repositories have been identified as conduits for malware and phishing scams,…

3 hours ago

Attackers Leverage Sidecar Container Injection Technique To Stay Stealthy

Kubernetes (K8s) is an open-source container orchestration platform designed to automate application container deployment, scaling, and running.  Containers are isolated…

5 hours ago

How to Utilize Azure Logs to Identify Threats: Insights From Microsoft

Microsoft's Azure platform is a highly acclaimed and widely recognized solution that organizations worldwide are leveraging. It is regarded as…

7 hours ago

Redline Malware Using Lua Bytecode to Challenge the SOC/TI Team to Detect

The first instance of Redline using such a method is in a new variant of Redline Stealer malware that McAfee…

20 hours ago

Threat Actor Claims Selling of Dell Database with 49M User Records

A threat actor reportedly sells a database containing 49 million user records from Dell, one of the world's leading technology…

23 hours ago