Category: Google|Nov 25, 2017 | Author: Admin

Android issue allows attackers to capture screen and record audio on 77% of all devices

Share on

Most of the Android devices (running Lolipop, Marshmallow, and Nougat) are exposed to an attack that exploits the MediaProjection service to capture the user’s screen and record system audio. By exploiting this issue, the attacker can simply fool a user into giving the proper rights to a malicious app.

Most of the Android devices (running Lolipop, Marshmallow, and Nougat) are exposed to an attack that exploits the MediaProjection service to capture the user’s screen and record system audio. By exploiting this issue, the attacker can simply fool a user into giving the proper rights to a malicious app.

Google launched the MediaProjection service to the Android Framework in Android 5.0 to give developers the capability to capture screen contents and record system audio. Before Android 5.0, developers required their apps to run with root privileges in order to use system protected permissions to get screen contents.

A report by MWR Labs describes:
To use the MediaProjection service, an application would simply have to request access to this system Service via an Intent. Access to this system Service is granted by displaying a SystemUI pop-up that warns the user that the requesting application would like to capture the user’s screen.

The main issue with MediaProjection service is that it is not reliant on permission, which makes it difficult to discover if an application is going to make use of the service.

This issue has been fixed in Android 8 Oreo only, users running Lollipop, Marshmallow or Nougat remain at risk. The only true fix at the moment is to upgrade to Oreo.

Sponsored Ads:

Comments:


Edge 125 arrives in Beta with sleeping tab improvements and other changes

Category: IT|May 1, 2024 | Author: Admin

Now the iPad opens

Category: Apple|Apr 30, 2024 | Author: Admin

Woke up locked out of Apple ID on iPhone

Category: Apple|Apr 29, 2024 | Author: Admin

Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin

Now Windows will be bothered about this too

Category: Microsoft|Apr 18, 2024 | Author: Admin

Test the new AI trick with Logitech

Category: IT|Apr 17, 2024 | Author: Admin
more