“Our primary focus was exposing pre-positioned threats on Android devices sold by United States (US) carriers, although our results affect devices worldwide.”the 38 vulnerabilities of a different nature could induce spying and factory resets.
“The vulnerabilities we discovered on devices offered by the major US carriers are the following: arbitrary command execution as the system user, obtaining the modem logs and logcat logs, wiping all user data from a device (i.e., factory reset), reading and modifying a user’s text messages, sending arbitrary text messages, getting the phone numbers of the user’s contacts, and more.”The devices tested by the researchers include ZTE, LG, Asus and Essential Phone. Almost all of them are distributed by major carriers like AT&T and Verizon.
“The problem is not going to go away, because a lot of the people in the supply chain want to be able to add their own applications, customize, add their own code. That increases the attack surface, and increases the probability of software error. They are exposing the end user to exploits that the end user is not able to respond to.”He further emphasized on these findings by highlighting that most users believe they would suffer only through the apps they download later. Whereas, according to what they discovered, most pre-installed apps already make the user vulnerable.
Then again, a Google spokesperson clarified in a statement that the vulnerabilities belonged to the third party applications, and not to the actual firmware.
“We would like to thank the security researchers at Kryptowire for their efforts to reinforce the security of the Android ecosystem. The issues they have outlined do not affect the Android operating system itself, but rather, third party code and applications on devices.”Yet again, the problem remains there as the end users have no options available to protect themselves from such vulnerabilities. Many of the pre-installed Android apps do not even uninstall. Hence, the users remain reliant on the updates and patches released by the manufacturers or the carriers.