Android Security Flaw Let Apps Access People's Cameras for Secret Video and Audio Recordings

A security flaw in Android smartphones from companies like Google and Samsung allowed malicious apps to record video, take photos, and capture audio, uploading the content to a remote server sans user permission.

The vulnerability was discovered by security firm Checkmarx, and was highlighted today by Ars Technica. The flaw had the potential to leave high-value targets open to having their surroundings illicitly recorded by their smartphones.

androidvulnerability


Android is meant to prevent apps from accessing the camera and the microphone on a smartphone without user permission, but with this particular exploit, an app could use the camera and the microphone to capture video and audio without express user consent. All an app needed to do was get permission to access a device's storage, which is commonly granted as most apps ask for this.

To demonstrate how the flaw worked, Checkmarx created a proof-of-concept app that appeared to be a weather app on the surface but was scooping up copious amounts of data in the background.

The app was able to take pictures and record videos even when the phone's screen was off or the app was closed, as well as access location data from the photos. It was able to operate in stealth mode, eliminating the camera shutter sound, and it could also record two-way phone conversations. All of the data was able to be uploaded to a remote server.

When the exploit was used, the screen of the smartphone being attacked would display the camera when recording video or taking a photo, which would let affected users know what was going on. It could be used secretly when a smartphone display was out of sight or when a device was placed screen down, and there was a feature for using the proximity sensor to determine when a smartphone was facedown.

Google addressed the vulnerability in its Pixel phones through a camera update that was launched back in July, and Samsung has also fixed the vulnerability, though it's not known when. From Google:

"We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure. The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners."

From Samsung:

"Since being notified of this issue by Google, we have subsequently released patches to address all Samsung device models that may be affected. We value our partnership with the Android team that allowed us to identify and address this matter directly."

According to Checkmarx, Google has said that Android phones from other manufacturers could also be vulnerable, so there may still be some devices out there that are open to attack. Google has not disclosed specific makers and models.

Since this is an Android bug, Apple's iOS devices are not affected by the security flaw.

It's not known why apps were able to access the camera without user permission. In an email to Ars Technica, Checkmarx speculated that it could potentially be related to Google's decision to make the camera work with Google Assistant, a feature that other manufacturers may have also implemented.

Popular Stories

Apple Vision Pro 2 Feature 2

Apple Reportedly Suspends Work on Vision Pro 2

Tuesday June 18, 2024 8:17 am PDT by
Apple has suspended work on the second-generation Vision Pro headset to singularly focus on a cheaper model, The Information reports. Apple was widely believed to have plans to divide its Vision product line into two models, with one "Pro" model and one lower-cost standard model. The company is said to have been deprioritizing the next Vision Pro headset over the past year, gradually...
apple watch series 9 display

Kuo: Apple Watch Series 10 to Get Larger Screen and Thinner Design

Monday June 17, 2024 1:20 am PDT by
This year's Apple Watch Series 10 will be thinner and come in larger screen sizes than previous models, according to Apple analyst Ming-Chi Kuo. In his latest industry note -10-and-98075c44ce92">shared on Medium, Kuo said the screen size options on the next-generation Apple Watch will increase from 41mm to 45mm, and from 45mm to 49mm, while being encased in a thinner design. For reference,...
2022 back to school apple feature

Apple's 2024 Back to School Sale Launching This Week

Monday June 17, 2024 12:27 pm PDT by
Apple will launch its annual Back to School promotion for university students in the United States and Canada this week, according to Bloomberg's Mark Gurman. Apple's back to school sales provide students with a free Apple gift card when purchasing a Mac or an iPad, and this year's promotion could help Apple push the new M2 iPad Air and M4 iPad Pro models. Last year, Apple offered U.S....
Apple Pay Later feature 1

Apple Discontinuing Apple Pay Later

Monday June 17, 2024 11:44 am PDT by
Apple is discontinuing Apple Pay Later, the buy now, pay later feature that it just launched last October. Apple Pay Later is being discontinued as of today, but people who have existing Apple Pay Later loans will be able to continue to pay them off and manage them through the Wallet app. Apple announced plans to end the feature in a statement provided to 9to5Mac, which also notes that...
iOS 18 CarPlay Feature

iOS 18 Adds These 5 New Features to CarPlay

Thursday June 13, 2024 7:44 am PDT by
Apple did not mention CarPlay during its WWDC keynote this week, but iOS 18 includes a handful of new features for the in-car software. Overall, there is not a whole lot new for CarPlay on iOS 18, with changes seemingly limited to the Messages and Settings apps so far. Below, we recap everything new for CarPlay on iOS 18. New for CarPlay on iOS 18 1. Contact Photos in Messages App...
iPod Nano vs iPod Pro Ad Feature 1

Apple Developing Thinner MacBook Pro, Apple Watch, and iPhone

Monday June 17, 2024 2:22 am PDT by
Apple intends to slim down the MacBook Pro, Apple Watch, and iPhone, with the new ultra-thin M4 iPad Pro a sign of the company's new design trajectory, according to Bloomberg's Mark Gurman. When the M4 iPad Pro was unveiled last month, Apple touted it as the company's thinnest product ever, and even compared it to the 2012 iPod nano to emphasize its slim dimensions. Writing in the latest ...
watchOS 11 Thumb 2 1

watchOS 11 Supports Automatic Nap Detection

Monday June 17, 2024 4:05 pm PDT by
watchOS 11 appears to include a new feature that allows an Apple Watch to automatically detect and record when you're taking a nap. As shared on Reddit, an Apple Watch owner took a nap and was able to see the sleep data recorded in the Health app, despite not putting the device in Sleep Mode. Right now, the Apple Watch only tracks and records sleep when it is in Sleep Mode, and there is no...

Top Rated Comments

drinkingtea Avatar
60 months ago
I love my iPhone.
Score: 28 Votes (Like | Disagree)
Mr. Awesome Avatar
60 months ago
And people still say Android is better...
Score: 26 Votes (Like | Disagree)
LeeW Avatar
60 months ago
Google - "Yeah whatever, whoever you are, your app is out there"

Apple - "Yeah, register, prove who you are, let us check the app before it gets released, Nah buggy and a resource hog, fix it, ok done, fine it's available on the store"

Android users - but I get a really open app store and can download anything I want, apple store is ****.
Apple users - I saw you in the shower last night.
Score: 24 Votes (Like | Disagree)
iamgalt Avatar
60 months ago
"security flaw"

Yeah, right. On a Google OS?
Score: 20 Votes (Like | Disagree)
osx86 Avatar
60 months ago
Another day, another major Android OS security flaw. But thats not even the real problem. The real issue is that most android phones wont get the proper updates to fix it, leaving millions permanently vulnerable.
Score: 20 Votes (Like | Disagree)
edgonzalez32 Avatar
60 months ago
The amount of people quick to **** on Android is absolutely ridiculous. Ya'll really need to chill with that ****. Yes, it's a major security flaw.

The article also states that Google already pushed out an update to patch the issue. As for other manufacturers putting out a fix, we already know carriers play a role in how fast can get patch updates for Android.

I'm a long time iOS user, was on a Pixel 2 for a year and a half. You know why? Because it's a great phone. And Android is a fantastic platform that can do A LOT of things better than iOS can. At least with an Android, you don't feel like you're using a device in a way the manufacturer wants you to, which is my biggest criticism of iOS as both a user and a UX Designer.

This crapping all over Android is absolutely ridiculous, especially in the forums on this site. Competition is good for both iOS and Android users. And Android does offer a ton of that. It makes both platforms better and gives users more choice. Don't sit here and try to act like you're above people that choose a platform that isn't the one you chose. Because it doesn't satisfy your needs doesn't mean it fails for someone else. You don't know their workflows, use cases, etc.
Score: 16 Votes (Like | Disagree)