Christopher Wade: Physical Attacks on Modern Android Smartphones
A DEF CON 31 talk on vulnerabilities that still exist in modern Android devices despite improved protections against physical access attacks.
The first part covers flaws in manufacturer-modified Recovery modes, which can allow privilege escalation to root and booting into the main Android system without unlocking the bootloader — using only a microSD card.
The second part examines a vulnerability in the secondary bootloader of a popular smartphone brand. By exploiting an issue in the USB stack, the researcher demonstrates how to achieve code execution and load a modified Android system without breaking device functionality.
The first part covers flaws in manufacturer-modified Recovery modes, which can allow privilege escalation to root and booting into the main Android system without unlocking the bootloader — using only a microSD card.
The second part examines a vulnerability in the secondary bootloader of a popular smartphone brand. By exploiting an issue in the USB stack, the researcher demonstrates how to achieve code execution and load a modified Android system without breaking device functionality.