Google's Fix for "Stagefright" Vulnerability Incomplete
Aug 14, 2015, 2:45 PM by Rich Brome @rbrome.bsky.social
A serious flaw has been found in Google's recent fix for the recently-disclosed "Stagefright" security issue in its Android OS. The issue lets malicious video content crash a phone, and can be triggered by automatic downloading of a video MMS. Google is distributing ad updated software patch to partners, and will update Nexus phones next month. The Stagefright issue allows a malicious video to access random software code on the device, thus potentially crashing the phone. It cannot easily be used to target specific code, thanks to a security feature built into Android called ASLR. ASLR randomizes the location of code in memory to keep these kinds of exploits from being able to target any specific system code and perform a specific intended action.
Comments
No messages

iPhone 15 Series Goes All-In on USB-C and Dynamic Island
Samsung S24 Series Adds More AI, Updates the Hardware
Android Will Prompt You To Update a Crashy App After a Crash
Motorola Gets Serious About Foldables with New RAZR Lineup
iOS 17 Brings Comprehensive Protection Against Unwanted Nude Images



