CnTechPost CnTechPost
  • News
    • Tech Industry
    • Gadgets
    • Software
    • Stocks
    • Crypto
    • Cars
    • Software
    • 5G
    • How To
  • Contact
  • About
  • CnEVPost

Home ยป Software

Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected

By Phate Zhang
Oct 4, 2019 at 2:51 PM UTC
0
0

At least 18 phone models are affected by a zero-day vulnerability in Googleโ€™s Android system that can give full control of the devices to Attackers, a member of Googleโ€™s Project Zero research group said on Thursday night.

A post from the security group suggests it found the bug last week, and attackers were exploiting it at that moment. The post notes the exploit requires no or minimal customization to root a phone thatโ€™s exposed to the bug.

Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost

Arstechnica notes that there are two different ways attackers can use the exploit: (1) when a target installs an untrusted app or (2) for online attacks, by combining the exploit with a second exploit targeting a vulnerability in code the Chrome browser uses to render content.

โ€œThe bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device,โ€ Project Zero member Maddie Stone wrote. โ€œIf the exploit is delivered via the Web, it only needs to be paired with a renderer exploit, as this vulnerability is accessible through the sandbox.โ€

The devices affected include Google's Pixel models, as well as phones from Chinese manufactures including Huawei, Xiaomi and OPPO.

Here is a โ€œnon-exhaustive listโ€ of vulnerable phones:

  • Pixel 1
  • Pixel 1 XL
  • Pixel 2
  • Pixel 2 XL
  • Huawei P20
  • Xiaomi Redmi 5A
  • Xiaomi Redmi Note 5
  • Xiaomi A1
  • Oppo A3
  • Moto Z3
  • Oreo LG phones
  • Samsung S7
  • Samsung S8
  • Samsung S9

The Android team says it has informed phone makers to issue a patch:

We have notified Android partners and the patch is available on the Android Common Kernel. Pixel 3 and 3a devices are not vulnerable while Pixel 1 and 2 devices will be receiving updates for this issue as part of the October update.

The researchers speculate the bug is being used by NSO, an Isreal-based group known to sell tools to authorities to exploit iOS and Android.

โ€œThis issue is rated as high severity on Android and by itself requires installation of a malicious application for potential exploitation,โ€ Tim Willis, another Project Zero member, wrote, citing Android team members. โ€œAny other vectors, such as via web browser, require chaining with an additional exploit.โ€

More on Software

Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
Huawei says HarmonyOS 2 surpasses 100 million users
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
Tencent resumes new user registration for WeChat
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
Honor of Kings upgrades rules, bans users under 12 from topping up
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
Tencent testing NokNok, a Discord-like social app for gamers
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
Tencent announces new measures to reduce impact of games on minors
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
WeChat suspends new user registration for personal accounts, expected to resume in early August
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
Huawei releases HMS Core 6.0
Android phones under threat of attackers full control, Google, Xiaomi, and Huawei devices affected-CnTechPost
TikTok becomes first app not owned by Facebook to reach 3 billion downloads
AndroidBugSecurity

Recent Posts

  • DeepSeek makes minor upgrades to its R1 reasoning model May 29, 2025
  • Chinese video platform iQIYI reportedly to lay off 20-40% of its workforce Dec 1, 2021
  • Xiaomi's MIUI surpasses 500 million monthly active users worldwide Nov 24, 2021
  • Education stocks soar with reports that China will resume after-school tutoring Nov 8, 2021
  • Huawei posts sales revenue of about $71.3 billion in first 3 quarters Oct 29, 2021
CnTechPost CnTechPost
CnTechPost.com
  • Home
  • Tech
  • Gadgets
  • Software
Subscribe
  • RSS Feed
About
  • About Us
  • Contact Us
  • Privacy Policy
Copyright ยฉ 2025 CnTechPost.