Massive Android security vulnerability revealed
A new Android vulnerability has been discovered by the University of Texas. It allows an attacker to bypass a smartphone lockscreen and gain access to the device.
The vulnerability exists in Android 5.x, before 5.1.1 build LMY48M.
By “manipulating a sufficiently large string in the password field when the camera app is active”, an attacker can destabilise the lockscreen – causing it to crash to the home screen.
After this is done, an attacker can gain access to the device.
To execute the attack, the attacker must have physical access to the device and the user must have a password set. Pattern configurations do not appear to be exploitable.
Full details about the vulnerability are available here.
More on Android
Massive Android vulnerability means hackers can take over your phone
Android Wear devices now work with iPhones