Hackers Can Use A Single Image To Remotely Hack your Android Device

Recently the security researchers discovered a new severe vulnerability which has the ability to make hackers to take over your smartphone using just a simple image using ExifInterface. Yes, it means that hackers can now remotely hack any Android device with the help of a single image.

Owners of Android devices should be on alert because innocent at first glance, the image obtained on the social network or messenger may compromise the privacy and security of your smartphone. On Tuesday 6th September 2016, Google has released the planned updates for Android, including correcting vulnerability “Quadrooter”. However, before that, on September 1st, the company corrected the previously unknown critical vulnerability which was discovered by the information security expert from SentinelOne Tim Strazzere.

Vulnerability reminds notorious Stagefright, allows to hack Android-powered device with a simple text message, the user may not even be aware of its receipt. Now, in order to carry out the attack, the attacker need only to send a malicious picture. The user does not even need to click on it – until the phone analyzes the image data, remotely the attacker can easily and quietly gain control over the infected device.

Vulnerability CVE-2016-3862 is caused due to an error when processing EXIF-data capture in Mediaserver application.

“Since the bug is triggered without much user interaction – an application only needs to load an image a specific way – triggering the bug is as simple as receiving a message or email from someone. Once that application attempts to parse the image (which was done automatically), the crash is triggered” Tim Strazzere said.

According to the researchers, an attacker can inject the vulnerability in the sent image which is a simple exploit to simply hack the device of the victim. Tim Strazzere wrote that the exploit for vulnerable devices, and, as it turned out, it works for Gchat, Gmail and most popular instant messengers and social networks applications. The vulnerability affects all devices running the Android versions from 4.4.4 Kitkat to 6.0.1 Marshmallow.