Skip to main content

Manufacturers’ Android modifications open security leaks, study shows

android_holes
Image used with permission by copyright holder

Researchers at North Carolina State University have discovered a vulnerability with a number of leading Android handsets that could allow hackers to access private data without having to get explicit user permission. According to the study, such a loophole could give malicious hackers the ability to “wipe out the user data, send out SMS messages, or record user conversation on the affected phones – all without asking for any permission.”

Recommended Videos

Unlike apps for iOS, which alert a user anytime the app wants to access some type of personal information, like location, Android apps use a permissions-based security system, which tells the user up-front what type of information to which the app may at some point need access. Users can then decide whether or not they want to install the app based upon the permissions granted.

The NCSU study shows that the modification of Android by some handset manufacturers creates a hole in the permissions infrastructure, which could allow hackers to access sensitive private information, or perform functions on the phone, even if an app doesn’t explicitly request permission to perform these activities.

“These features are standard and make the phone more user-friendly,” said Xuxian Jiang, assistant professor of computer science at NCSU. “They make the phones more convenient to use, but also more convenient to abuse.”

Using their “Woodpecker” diagnostics tool, which checks to see if an app can perform a function for which it has no permission, the researchers found the following devices to be most vulnerable: HTC Evo 4G, HTC Wildfire S, HTC Legend, Motoroal Droid and Droid X, Samsung Epic 4G, Google Nexus One and Nexus S. Both Google and Motorola have responded to the researchers, confirming their discovery. Samsung and HTC, however, have given the team “major difficulties.”

Despite their findings, the researchers say that manufacturers should not necessarily be condemned for including these loopholes. In addition, they say all is not lost with Android’s permissions-based system.

“Though one may easily blame the manufacturers for developing and/or including these vulnerable apps on the phone firmware, there is no need to exaggerate their negligence,” the team writes in the study. “Specifically, the permission-based security model in Android is a capability model that can be enhanced to mitigate these capability leaks.”

Read the full study here (pdf).

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Does Nothing’s new CMF phone bend or break in durability test?
The CMF Phone 2 Pro undergoes a durability test.

Nothing’s new CMF Phone 2 Pro has been very warmly received since its launch last month, with many loving it for its fun design and decent specs for a handset costing just $279.

A new Android phone like this was always going to attract the attention of YouTuber Zack Nelson -- he of JerryRigEverything -- who’s just dropped a new durability video featuring Nothing’s latest budget device.

Read more
How to watch the Samsung Galaxy S25 Edge launch event
Close-up view of the camera module on Samsung Galaxy S25 Edge.

Samsung is about to launch its most ambitious smartphone in years later this week, one that brings back the fondly remembered “Edge” moniker. The Korean electronics giant’s next offering is the Galaxy S25 Edge, an ultra-slim phone that was first showcased earlier this year and will finally get the full launch treatment. 

The online event kicks off at 5:00pm PT / 8:00pm ET on May 12 for those of you in the US, instead of multiple on-ground events across different regions.

Read more
Honor 400 series phones will turn pictures into fun videos using AI
Person using the cameras on a Honor 400 series phone.

Chinese smartphone brand, Honor, is usually at the helm of camera-centric smartphone innovations and delivering ultra-slim foldable phones. For its next adventure, the company is also embracing a playful side of AI that turns still images into short clips. 

Leveraging the Google Cloud AI stack, the new feature will make its debut on the upcoming Honor 400 series smartphones. Set for an official launch on May 22, the Honor 400 and its Pro trim will come equipped with a massive 200-megapixel AI-enhanced camera, as well.

Read more