Skip to main content

Manufacturers’ Android modifications open security leaks, study shows

android_holes
Image used with permission by copyright holder

Researchers at North Carolina State University have discovered a vulnerability with a number of leading Android handsets that could allow hackers to access private data without having to get explicit user permission. According to the study, such a loophole could give malicious hackers the ability to “wipe out the user data, send out SMS messages, or record user conversation on the affected phones – all without asking for any permission.”

Unlike apps for iOS, which alert a user anytime the app wants to access some type of personal information, like location, Android apps use a permissions-based security system, which tells the user up-front what type of information to which the app may at some point need access. Users can then decide whether or not they want to install the app based upon the permissions granted.

Recommended Videos

The NCSU study shows that the modification of Android by some handset manufacturers creates a hole in the permissions infrastructure, which could allow hackers to access sensitive private information, or perform functions on the phone, even if an app doesn’t explicitly request permission to perform these activities.

“These features are standard and make the phone more user-friendly,” said Xuxian Jiang, assistant professor of computer science at NCSU. “They make the phones more convenient to use, but also more convenient to abuse.”

Using their “Woodpecker” diagnostics tool, which checks to see if an app can perform a function for which it has no permission, the researchers found the following devices to be most vulnerable: HTC Evo 4G, HTC Wildfire S, HTC Legend, Motoroal Droid and Droid X, Samsung Epic 4G, Google Nexus One and Nexus S. Both Google and Motorola have responded to the researchers, confirming their discovery. Samsung and HTC, however, have given the team “major difficulties.”

Despite their findings, the researchers say that manufacturers should not necessarily be condemned for including these loopholes. In addition, they say all is not lost with Android’s permissions-based system.

“Though one may easily blame the manufacturers for developing and/or including these vulnerable apps on the phone firmware, there is no need to exaggerate their negligence,” the team writes in the study. “Specifically, the permission-based security model in Android is a capability model that can be enhanced to mitigate these capability leaks.”

Read the full study here (pdf).

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
A company you wouldn’t expect just beat Apple as the No. 1 smartwatch brand
A Huawei smartwatch on a person's wrist.

Apple’s wearable devices, and specifically its smartwatches, are often deemed the default best. The ecosystem around the Apple Watch is often cited as the core convenience, but there’s no doubt that Apple deserves merit for health innovation and technical prowess, too.

It, therefore, comes as a surprise that a sanction-battered company with a far smaller presence in the West has managed to topple Apple and nab the crown of the world’s biggest wrist-worn device brand. The company in question is Huawei.

Read more
This mad phone does something unexpected when it gets cold
A promotional image showing the back of the Realme 14 Pro.

Realme certainly knows how to make an impression with the design of its phones. From Coca-Cola to Claude Monet, the brand always seems keen to embrace unusual trends, and for the Realme 14Pro series, it has created something we’ve not seen before — a rear panel that changes color with the ambient temperature.

I’ll let Realme explain what it does: “It employs advanced thermochromic pigments that react to temperature changes. When the temperature drops below 16 degrees Centigrade (61 degrees Fahrenheit), the phone’s back cover transitions from pearl white to a vibrant blue, reversing as environmental temperatures rise.”

Read more
5 things I want to see from the iPhone in 2025
iPhone 16 Pro Max next to the 16 Plus, 16 Pro and regular iPhone 16

As the year winds down, it's the perfect time to take a look back and reflect. After all, we did get some pretty exciting smartphones in 2024, and Apple went above and beyond with the iPhone 16 series.

But as we inch closer to the new year, there are some things I hope that Apple will take into consideration with the iPhone. Here’s what I am hoping to see with the iPhone in 2025.
Faster charging speeds

Read more