Giải trí

2/3 of Android users in the world are at risk because of this vulnerability-Information Technology

Saturday, May 7, 2022 09:00 AM (GMT+7)

Recently, Check Point security researchers discovered several vulnerabilities in the ALAC format, allowing attackers to remotely execute code on the phone.

Apple Lossless Audio Codec (ALAC) is an audio encoding format developed by Appleand first introduced in 2004.

In late 2011, Apple shared the source code for ALAC, and since then the format has been embedded in many devices and media players.

Apple still repeatedly releases security updates and patches for ALAC, but the shared source code has not been patched since 2011.

According to Check Point researchers, Qualcomm and MediaTek (the world’s two largest mobile chipset manufacturers) have used the ALAC audio encoding format in mobile devices, making millions of users Android privacy risks.

According to IDC, 48.1% of all Android phones sold in the US used MediaTek chipsets as of Q4 2021, while Qualcomm currently holds 47% of the market.

2/3 of Android users in the world are at risk because of this vulnerability - 1

Millions of Android phone users are at risk of being hacked. Photo: Tieu MINH

This study dubbed “ALHACK” shows that two-thirds of all smartphones sold in 2021 are vulnerable.

A vulnerability inside ALAC allows attackers to remotely execute code (RCE) on mobile devices via malformed audio files. Besides, crooks can also take control of multimedia data, including live streaming using the victim’s phone.

In addition, malware can use this vulnerability to elevate privileges and gain access to the user’s multimedia data or chats.

Before releasing this information, Check Point informed MediaTek and Qualcomm and worked closely with both vendors to ensure this vulnerability was fixed.

Currently, both MediaTek and Qualcomm have released patches for users from December 2021.

You are reading the article 2/3 of Android users in the world are at risk because of this vulnerability-Information Technology
at Blogtuan.info – Source: 24h.com.vn – Read the original article here

Back to top button