Skip to main content

Researchers find Android vulnerability that can render devices inoperable

android vulnerability mediaserver top 5 best games meek mill bike life siegefall
Image used with permission by copyright holder
Another day, another Android exploit. Just earlier this week, a security researcher disclosed a debilitating flaw in Android multimedia playback tool Stagefright, and now researchers at Trend Micro have discovered a new vulnerability that they claim is potentially just as destructive. According to the firm’s report, an attack leveraging the exploit could, if properly executed, render an Android device “totally silent and non-responsive.”

The vulnerability resides in mediaserver, Android’s background service responsible for indexing videos, pictures, and audio. Trend Micro says that with the right know-how, a hacker could craft a malformed Matroska (usually .mkv) container capable of crashing mediaserver — and the entire operating system, subsequently — when it attempts to process the file. Researcher Wish Wu writes in a blog post that during testing, the exploit affected devices running Android 4.3 and above — about 57 percent of all Android smartphones and tablets by Google’s last count.

In its report, Trend Micro envisions increasingly dire scenarios from missed ring tones to permanently locked phones, arising from the exploit. The researchers even theorize a malicious app could render devices inoperable by loading the malformed file at boot. But Google, which was informed of the exploit last week, is a bit more measured. “While our team is monitoring closely for potential exploitation, we’ve seen no evidence of actual exploitation,” a spokesperson told Mashable. “Should there be an actual exploit of this, the only risk to users is temporary disruption to media playback on their device.”

Ultimately, the vulnerability, while worrisome, isn’t quite as dire as the Stagefright exploit, which allows hackers to hijack and install malware on phones with a simple text message. Still, Google says it’s working on a fix. In the meantime, it suggests that anyone affected by the mediaserver bug try navigating away from the malicious website or uninstalling the misbehaving application.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The Oppo Find N will be among the first foldables to try Android 13 Beta 1
Oppo Find N camera open.

The promises of Android 13 are enough to get any Android user excited, but Oppo smartphone owners won't have to wait to see what the next major update to the operating system has in store. The Find N is Oppo's flagship foldable and already supports the Android 13 Beta 1 for users in China while the Find X5 Pro supports the first beta across the globe.

Although it's certainly exciting to have the chance to try out the Android 13 Beta on a regular smartphone, Google showcased the software update's focus on tablets and foldables at the company's I/O keynote yesterday. Specifically, the Find N was highlighted during the presentation and now owners will be able to see what the big deal is for themselves.

Read more
Android 12L is available, but you can’t use it on any tablets
Android 12L changes in action.

Google is finally getting serious about Android tablets with the public release of Android 12L, but the company is still lagging on the effort it seems. Tailored for tablets and foldables to make the most out of their larger screen real estate, the Android 12L update is currently only available for Google’s Pixel phones. No tablet out there, even Samsung’s beastly Snapdragon 8 Gen 1-powered Galaxy Tab S8, is getting it anytime soon.

As per Google’s blog post, the update will arrive for foldables and tablets from Samsung, Lenovo, and Microsoft “starting later this year.” There isn’t a month specified, and the Android 12L rollout will no be uniform, as each company will take time to customize and implement Android 12L in line with their own in-house skin. Google says it will create more new features and experiences for tablets with Android 13, which will arrive later this year.

Read more
You can download Android 13’s first Developer Preview now
Android 13 concept.

Google today announced Android 13, the next major update to its Android operating system. While the company hasn't shared a lot of what is coming down the pipeline for consumers, it did hint that it would be focusing on a private operating system as it tries to win over converts from Apple's famously private iOS.

"People want an OS and apps that they can trust with their most personal and sensitive information. Privacy is core to Android’s product principles, and Android 13 focuses on building a responsible and high-quality platform for all by providing a safer environment on the device and more controls to the user," Google's Dave Burke, vice president of engineering said in a blog post.

Read more