More Stagefright Fun

Tech news
Post Reply
Adam
Posts: 2242
Joined: Wed Oct 23, 2013 9:50 pm

More Stagefright Fun

Post by Adam »

Remember that time when the stage fright vulnerability had the potential to impact one billion Android devices? That was bad, but was easily mitigated by first turning off autodownload for MMS, then later by various carriers. That was fun.

Turns out the fun isn't over. There were several iterations to fixing this issue, the first of which had some bugs but overall were still subject to the aforementioned mitigations. Now more vulnerabilities have been found which can be exploited via web pages, not just malicious MMS messages.

This is only fixed in the newest version of Android so anyone with a device older than a Nexus 5x/6p is vulnerable. Hopefully Google at least patches their older supported devices. Other Android OEMs will likely never do that.

https://exploit-db.com/docs/39527.pdf
Post Reply