Ryan Johnson, Mohamed Elsabagh & Angelos Stavrou: Android Phones Vulnerable Right Out of the Box
A DEF CON 31 talk on the security of low-cost prepaid Android smartphones. Researchers analyzed 21 devices sold by U.S. carriers and 11 unlocked models.
They discovered serious vulnerabilities in several devices, including arbitrary command execution, access to system files, factory reset abuse, GPS data leaks, and exposure of unique device identifiers.
The attack only requires installing a regular third-party app with no special permissions. Due to flaws in pre-installed software, such apps can escalate privileges and access data beyond their intended permissions.
They discovered serious vulnerabilities in several devices, including arbitrary command execution, access to system files, factory reset abuse, GPS data leaks, and exposure of unique device identifiers.
The attack only requires installing a regular third-party app with no special permissions. Due to flaws in pre-installed software, such apps can escalate privileges and access data beyond their intended permissions.