RSS
 

Posts Tagged ‘hackers’

Security firm warns Android camera vulnerability lets hackers spy on phone owners

21 Nov

Security analyst firm Checkmarx has detailed the discovery of an Android security issue that enables hackers to access a smartphone’s camera app, existing videos and images, audio from the microphone and location information pulled from EXIF data. Though the issue has been fixed on Google and Samsung phones, it remains in many camera apps from other vendors

The security researchers first analyzed the Google Camera app included on the Pixel smartphones. Upon discovering the security vulnerability, which involves ‘manipulating specific actions and intents,’ they found the same issue could be exploited in the Samsung Camera app included in its various smartphone models.

The vulnerability is extensive, according to the researchers. Hackers can access the camera app, use it to capture videos and photos even if the display is turned off or a call is in progress and access content saved to the phone. In addition to accessing the images, hackers could pull the location information from image metadata and use that to locate the handset’s owner.

The exploit introduces a number of privacy issues for users; attackers could use the video recording functionality to record a phone call, for example, and could retrieve sensitive images from the user’s phone for blackmail purposes.

According to Checkmarx, Google confirmed that the issue isn’t limited to the Pixel phones and that it is working with its Android partners ‘to coordinate disclosure.’ Both Google and Samsung released fixes for the security issue in their respective camera apps before Checkmarx published its report. It’s unclear how many phones from other vendors may still be vulnerable to the exploit, however.

Articles: Digital Photography Review (dpreview.com)

 
Comments Off on Security firm warns Android camera vulnerability lets hackers spy on phone owners

Posted in Uncategorized

 

iPhone X bug lets hackers steal deleted photos

16 Nov

If you have any particularly embarrassing or otherwise compromising photos on your iPhone you might want to think twice about how to keep them from being discovered by someone else. Simply deleting them might not be enough.

A vulnerability allowing hackers to access deleted photos and other files on the iPhone X was discovered by two researchers this week at the Pwn2Own hacking contest for finding iOS and Android bugs.

Richard Zhu and Amat Cama demoed the issue by connecting the iPhone X with iOS 12.1 to a malicious Wi-Fi network and exploiting a vulnerability in a so-called just-in-time (JIT) compiler which is designed to help iPhones to perform certain tasks faster.

The couple could then retrieve a photo from the Photo app’s Recently Deleted album where images are stored for 30 days after you delete them from the camera roll. This feature allows users to recover deleted photos should they have a change of mind. Through the same method other files processed by the JIT compiler could be accessed as well.

Zhu and Cama received a $ 50,000 reward for their findings and Apple has been informed of the bug. According to Forbes, the issue has yet to be fixed, though.

Articles: Digital Photography Review (dpreview.com)

 
Comments Off on iPhone X bug lets hackers steal deleted photos

Posted in Uncategorized