Android users Please note that your camera is turned on and secretly photographed the camera!

Android users Please note that your camera is turned on and secretly photographed the camera!

Japanese actress selfie some time ago because the pupil was brutally exposed address tracking heat has not in the past.
It is once again in leaked photos of personal information being threaten.
Android camera recently exposed a loophole, this is not only the photos leaked address.
It is also possible to record video quietly in case you have lock screen.
Think too horrible.

No authority can also turn on the camera

Android App camera appears in a new vulnerability, at least tens of millions of Android devices affected by this vulnerability to cause other App in the absence of the necessary permissions can shoot video, photo and GPS data is extracted from the reservoir .

Android App will usually open the camera and many other features for use other App on the same device, but in order to use these functions, other App must obtain the appropriate permissions in advance.

For Google and Samsung, Checkmarx researchers today disclosed a new vulnerability, even if the other did not get permission to Google App App, and they, too, can take pictures, record video capture device or location.

Under normal circumstances, when you download a new application is installed for the first time there will be a variety of open permission requests, including contacts, location, record video and take pictures and so on. With the improvement of safety awareness, many people are reluctant to provide these permissions, but chose to refuse, but this does not mean you can sit back and relax.

No authorization is still able to quietly record video?

All this stems from the Android system comes with a new vulnerability camera that could lead to other applications on the phone to record a video camera in the case of obtaining authorization, take pictures and get location data.

The vulnerability called CVE-2019-2234, researchers found that after conducting experiments, can be combined with a specially crafted application to manipulate photographs and Android devices to record video capabilities.

As for what this special application is it? It was made by researchers at a weather class App, just install it on your Android phone, you can be photos, videos and sound recordings quietly sent back to the command and control server researchers.

So long as the criminals want to take advantage of this vulnerability requires that any development of a just any type of App, Android phone once installed, you can do whatever they want.

Android users Please note that your camera is turned on and secretly photographed the camera!

And the Solution

Silent most terrible.

该漏洞十分危险,因为它可以允许没有应用权限的App执行以下操作:

1.在手机锁定或屏幕关闭的情况下拍摄照片并录制视频。
2.通过存储的照片提取GPS位置数据。
3.即使在拍照和录制视频时,也能收听到双向对话。被勒索的潜在可能太大了!
4.将相机快门静音,让受害者在拍照时听不到声音。
5.传输存储在SD卡中的历史视频和照片。

攻机者利用该漏洞可以控制受害者的相机,在拍照时静音,没有一点声音,你的照片和视频就发送到犯罪分子的服务器上了。

即使在手机锁屏的情况下,攻机者依然可以打开拍照和录制视频的功能。

现在大多数智能手机的拍照功能都会自动存储GPS位置,那么受害者的详细地址也会很轻松被暴露。

此外,再加上者可以将SD卡中的历史照片和数据传输到攻机者的服务器上,泄露的数据只会更多。

研究人员于今年7月向Google报告了此漏洞,Google将此漏洞定为高危级别,并通过Google Play商店发布了更新修复,并向其它Android供应商提供了补丁程序。

Checkmarx于2019年7月4日向Google指出了该漏洞,7月23日,Google将此漏洞提升为“高危漏洞”级别。

8月1日,Google证实了Checkmarx研究人员怀疑的漏洞的确存在,Google相机确实会影响其它搭载安卓系统的移动设备,该漏洞被命名为CVE-2019-2234。

8月下旬,Google确认三星设备的相机受到了影响,两家公司都批准了公开此漏洞的存在。

Google公司称,相机应用程序中的漏洞已经在2019年7月修复并通过Google Play商店更新,同时也为其它供应商提供了补丁。

“我们很感激Checkmarx引起了我们对这个问题的关注,并且与Google及安卓的供应商协商披露了这一问题。该问题已经在7月份解决,我们对Google Play商店的Google相机进行了更新,所有的合作伙伴都可以使用这个补丁。”

Here, it is strongly recommended that all users upgrade to the latest version of Android, to ensure that use of the device is up to date on your camera App.

Reference article: Android traced to a serious flaw: the application can make a secret video recording, call monitoring

Finally, here small share also included a copy of your finishing Android studying architecture PDF + Video + Interview + document source notes , as well as advanced fabric technology advanced brain maps, thematic interview Android development resources , advanced materials advanced architecture to help you enhance learning Advanced, saving everyone time online in search of information to learn, you can learn to share with close friends.

Android architecture video + BAT interview topic PDF + study notes

Guess you like

Origin blog.51cto.com/14332859/2452295