Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

The Samsung Galaxy S5 is one of the devices that is vulnerable to Metaphor, a new Android flaw. AP Photo/Lee Jin-man

This Android flaw could mess up your smartphone within 20 seconds

Another reminder to be careful of what you click on if you’re using an older device.

UP TO 275 MILLION Android devices could be at risk to a security flaw which installs malware and access your phone.

The flaw dubbed Metaphor works on devices running Android 5.0 – 5.1 as well as version 2 was discovered by Israeli security firm NorthBit.

The flaw is based on the Stagefright security flaw, which was originally discovered back in July, and affected close to a billion devices.

While that allowed attackers to infect a phone by sending a text message and exploiting the auto-loading feature, the process required to set it up was deemed impractical to do it consistently.

Metaphor doesn’t have that problem and Northbit claim it’s able to reliably compromise Android devices using this method. If the user visits a malicious website with a malicious MPEG-4 video, clicking on it will send a raft of data from the device back to the attacker’s computer. 

Depending on the device being affected, the process can take as little as 20 seconds to work.

The flaw is in media parsing which is done to retrieve metadata like video length, the title, and subtitles. This means the video doesn’t even need to be played for the flaw to be exploited.

Gil Dabah / YouTube

The saving grace for Android users is the attack code must be tailored to work on a specific Android device, making a universal exploit difficult to create, but the attack would only need minor modifications to work on different devices.

The flaw was tested on a Nexus 5 with stock firmware but managed to work on various versions of Android running on devices like the Samsung Galaxy S5, LG G3 and the HTC One.

Those devices with a security patch from 1 October 2015 and later are safe, but the issue is how many devices aren’t and can’t upgrade. Outside of Google’s own Nexus range, when an Android device gets upgraded depends on the manufacturer, and that can take a couple of months after release to happen.

Only 2.3% of Android users have the latest version Marshmallow (version 6.0), 36% are using Lollipop (version 5.0) while the remainder are using older versions. Many devices are older and unable to update to the latest version placing them at risk.

As always, most of these issues can be avoided once you stick to official sites and apps. If you ever get an email or message that looks suspicious, trust your gut instinct and ignore it, especially if you’re using an older device.

Android breakdown Android Developers Android Developers

Read: Facebook used different trailers for Straight Outta Compton based on race >

Read: Make sure you don’t ignore those download requests on your iPhone tonight >

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
9 Comments
    Install the app to use these features.
    Mute Deaglán MacThóirdealbaigh
    Favourite Deaglán MacThóirdealbaigh
    Report
    Mar 22nd 2016, 5:08 PM

    So my Samsung S5 which I still look at as a mighty phone altogether is now an “older device”. I call a Nokia 3210 an “older device”. Past it at 31. Jesus.

    55
    Install the app to use these features.
    Mute Byyys
    Favourite Byyys
    Report
    Mar 22nd 2016, 5:45 PM

    The Finnish company Nokia will apparently launch new Android-powered smartphones in 2016…
    (wont have any Windows software) It;s all very rumour-tastic but certainly interesting none the less.

    14
    Install the app to use these features.
    Mute tax slave
    Favourite tax slave
    Report
    Mar 22nd 2016, 7:44 PM

    Had thy done it at the start thy still be KING

    8
    See 2 more replies ▾
    Install the app to use these features.
    Mute Brendan McGill
    Favourite Brendan McGill
    Report
    Mar 23rd 2016, 5:18 AM

    That’s so true

    1
    Install the app to use these features.
    Mute Rehabmeerkat
    Favourite Rehabmeerkat
    Report
    Mar 23rd 2016, 4:54 PM

    Nokia isn’t a rumour. They have confirmed they are returning to the smartphone market in 2017. Thats when their agreement with Microsoft ends

    1
    Install the app to use these features.
    Mute Eoin Fleming
    Favourite Eoin Fleming
    Report
    Mar 22nd 2016, 5:57 PM

    Weren’t they bought by Samsung?

    1
    Install the app to use these features.
    Mute Liam Coyle
    Favourite Liam Coyle
    Report
    Mar 22nd 2016, 5:59 PM

    Microsoft bought them.

    15
    Install the app to use these features.
    Mute Byyys
    Favourite Byyys
    Report
    Mar 22nd 2016, 6:11 PM

    Not Samsung…Nokia entered into a pact with Microsoft in 2011 to exclusively use its Windows Phone platform on future phones. In September 2013, Microsoft announced that it would acquire Nokia’s mobile phone business as part of an overall deal totaling €5.44 billion euro. Last year Microsoft wrote off billions of dollars to the tune of $7.6 billion nearly the full amount it payed for Nokia phones and its patents. A clause in this deal meant Nokia is unable to launch a model under its own brand name until Q4 2016.

    Nokia has a new video called “Our vision”.. could possibly be an Android Nokia C1 in the making.
    https://www.youtube.com/watch?v=aYm7hh9ys0c

    7
    Install the app to use these features.
    Mute Eoin Fleming
    Favourite Eoin Fleming
    Report
    Mar 22nd 2016, 5:58 PM

    @byys

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds