We are experiencing some turbulent days negatively as far as security and privacy of Android concerned. After discovering the most serious security failure has been seen on the platform, by which basically puts at risk the security of our terminals through a short video with malware inside, which makes its extremely simple spread. Today, similar to that presented by Zimperium way, Trend Micro reports a vulnerability that affects Android all devices in between version 4.3 and Android 5.1.1 Jelly Bean Lollipop , the last available.

More than 50% of Android users are vulnerable to exploit mediaserver

Google is aware of the vulnerability of Android, since was reported in May . Despite this, Mountain View company has not yet submitted a patch to the Android Open Source Project , so that all terminals to be launched today to keep coming without solving the problem. The operation of the exploit is relatively simple, and can be activated in two ways. With applications installed on the terminal or through a web page created with the intention of compromising the stability of the terminal . Because stability is the issue. The application contains a malicious MKV media file that runs at startup and causing erratic behavior in the system. With a MKV read by Chrome, the effect is similar .

They are produced from service mediaserver , responsible for indexing the media terminal . Unable to process the malicious MKV, each time you run mediaserver , a problem may occur within the system that causes the operation of the terminal is very unstable. This causes the volume of the device is disabled, which will not receive any audible notification, such as messages or calls. Even listening to a call. In addition, If the phone is locked, we can not turn it on and use it normally , and if he were already being used, you can suffer many slowdowns. Shown here:

It is unlikely that this can be used in practice, but as they say in Trend Micro, could be used to threats that target paying users attackers who are behind the service.

Recommended