Android Security Hole Grows

Android Security Hole Grows

In March, security researchers at Skycure discovered a theoretical attack that involves the exploitation of two Android features that can be used together to take complete control over a victims phone or tablet. Now, those same researchers believe they’ve found event more ways to exploit more versions of the Android OS.

In March, Skycure said they believed 66 percent of Android phones and tablets could be hacked; now the number has been increased to 95.4 percent, or 1.34 billion devices.

By using an Accessibility Clickjacking Exploit, the researchers were able to leverage Android feature “Accessibility Service” along with a second feature built into the Android OS that allows you to draw over other apps. According to the security firm, all versions of the Android OS that came before 6.x Marshmallow are vulnerable to this clickjacking hack.

In order to tap into the vulnerability, a hacker would create a game or application that would run in an overlay window on top of the Android home screen. While the app was running, it would open up the Accessibility Services settings. The game would trick the user into tapping areas of the overlay screen that would also be recognized in the underlying screen. Using this method, an attacker could also trick you into tapping the right sequence of settings to hand over control of your phone to a remote hacker.

This clickjacking method could allow the hacker to invisibly open and close settings and open malicious webpages that can install malicious software onto the phone or tablet. Skycure says this technique could also trick users into unknowingly approve the service’s permissions such as Device Administrator access.

“After presenting this research at RSA, confirmed on all Android versions through KitKat, it occurred to me that there may be a way to also run this on Android devices running Lollipop. My team was then able to test this and verify that Lollipop is also vulnerable to Accessibility Clickjacking,” Yair Amit, CTO and co-founder of Skycure, said in a blog post.

Google has acknowledged the vulnerabilities brought forward by Skycure calling it, “an example of nefarious use of genuine tech.” Google has turned off, by default, the overlay feature in the Android 6.x OS. Users who want to take advantage of overlay screens in Android 6.x and above will have to opt-in to the feature.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • Brivo, Eagle Eye Networks Merge

    Dean Drako, Chairman of Brivo, the leading global provider of cloud-native access control and smart space technologies, and Founder of Eagle Eye Networks, the global leader in cloud AI video surveillance, today announced the two companies will merge, creating the world’s largest AI cloud-native physical security company. The merged company will operate under the Brivo name and deliver a truly unified cloud-native security platform. Read Now

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.