newsreport stagefright patch doesnt fix 950 million vulnerable devices
News

Report: Stagefright patch doesn’t fix 950 million vulnerable devices

The patch for Android's Stagefright vulnerability won't actually protect your phone, some security researchers say. According to Jordan Gruskovnjak and Aaron Portnoy of Exodus Intelligence, a malformed MP4 file can still create a buffer overflow, a vulnerability that could then be used to compromise 950 million Android phones.

The Exodus blog post walks through the vulnerability. A function in libStagefright reads two values from an MP4 file's header, chunk_size and chunk_type, as 32-bit integers. If the header returns a value of 0x01 for chunk_size, then a 64-bit value is read from the MP4 instead. According to the researchers, if an MP4 is crafted with a chunk size of 0x1fffffff (or any other value outside the bounds of a 32-bit integer), a flaw in the Stagefright patch's boundary-checking code means it's still possible to cause a buffer overflow.

Exodus says it notified Google of its findings on August 7. The company asked Google for a timeframe for another fix, but has not received a response. Since the Stagefright vulnerabilities were originally reported to Google in April, and it's been more than 90 days since that original disclosure, Exodus has decided to make the results of its research public. For now, even patched Android devices appear to remain vulnerable to the bug.

Ben Funk

Ben Funk

Sega nerd and guitar lover

Latest News

Criminals Already Misuse ChatGPT, Europol Warns
News

Criminals Already Misuse ChatGPT, Europol Warns

Apple Rolls Out iOS 16.4 - The 4th Major Update to iOS 16
News

Apple Rolls Out iOS 16.4 – The 4th Major Update to iOS 16

Apple launched its fourth major update to iOS 16, initially rolled out in September 2022. The newly released iOS 16.4 features updates that add security keys for Apple ID. iOS...

c-charge green revolution
Blog, Cryptocurrency, Listing, Sustainability

Eco-crypto C+Charge Raises $3.56M – Under 2 Days Before Presale Ends!

Eco-cryptocurrencies have indeed taken the crypto market by storm with their performances. Among these coins is the revolutionary token called C+Charge (CCHG). CCHG is one of the eco-crypto coins that...

ripple price prediction
Blog, Cryptocurrency, Investments, News

XRP Price Prediction – Ripple is the Big Winner in the Recent Crypto Bull Market!

lovehateinu
Blog, Cryptocurrency, Investments

Why LHINU and TAMA Are the Best Meme Coins to Buy in 2023

Shuffle Turns Shoppable: Pinterest Announces New Integrations
News

Shuffle Turns Shoppable: Pinterest Announces New Integrations

OpenAI Grants ChatGPT Access to Applications With New Plugins
News

OpenAI Grants ChatGPT Access to Applications With New Plugins