Android Security Flaw Let Apps Access People's Cameras for Secret Video and Audio Recordings

A security flaw in Android smartphones from companies like Google and Samsung allowed malicious apps to record video, take photos, and capture audio, uploading the content to a remote server sans user permission.

The vulnerability was discovered by security firm Checkmarx, and was highlighted today by Ars Technica. The flaw had the potential to leave high-value targets open to having their surroundings illicitly recorded by their smartphones.

androidvulnerability


Android is meant to prevent apps from accessing the camera and the microphone on a smartphone without user permission, but with this particular exploit, an app could use the camera and the microphone to capture video and audio without express user consent. All an app needed to do was get permission to access a device's storage, which is commonly granted as most apps ask for this.

To demonstrate how the flaw worked, Checkmarx created a proof-of-concept app that appeared to be a weather app on the surface but was scooping up copious amounts of data in the background.

The app was able to take pictures and record videos even when the phone's screen was off or the app was closed, as well as access location data from the photos. It was able to operate in stealth mode, eliminating the camera shutter sound, and it could also record two-way phone conversations. All of the data was able to be uploaded to a remote server.

When the exploit was used, the screen of the smartphone being attacked would display the camera when recording video or taking a photo, which would let affected users know what was going on. It could be used secretly when a smartphone display was out of sight or when a device was placed screen down, and there was a feature for using the proximity sensor to determine when a smartphone was facedown.

Google addressed the vulnerability in its Pixel phones through a camera update that was launched back in July, and Samsung has also fixed the vulnerability, though it's not known when. From Google:

"We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure. The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners."

From Samsung:

"Since being notified of this issue by Google, we have subsequently released patches to address all Samsung device models that may be affected. We value our partnership with the Android team that allowed us to identify and address this matter directly."

According to Checkmarx, Google has said that Android phones from other manufacturers could also be vulnerable, so there may still be some devices out there that are open to attack. Google has not disclosed specific makers and models.

Since this is an Android bug, Apple's iOS devices are not affected by the security flaw.

It's not known why apps were able to access the camera without user permission. In an email to Ars Technica, Checkmarx speculated that it could potentially be related to Google's decision to make the camera work with Google Assistant, a feature that other manufacturers may have also implemented.

Popular Stories

New Things Your iPhone Can Do in iOS 18

18 New Things Your iPhone Can Do in iOS 18.2

Wednesday November 27, 2024 5:05 am PST by
Apple is set to release iOS 18.2 in early December, bringing the second round of Apple Intelligence features to iPhone 15 Pro and iPhone 16 models. This update brings several major advancements to Apple's AI integration, including completely new image generation tools and a range of Visual Intelligence-based enhancements. There are a handful of new non-AI related feature controls incoming as...
iphone 16 pro models 1

12 Reasons to Wait for Next Year's iPhone 17

Friday November 29, 2024 5:17 am PST by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different – already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
Whatsapp Feature

WhatsApp to Drop Support for These iPhones Starting May 2025

Monday December 2, 2024 2:57 am PST by
WhatsApp is set to end support for iOS versions older than iOS 15.1 from May next year, removing the chat platform's compatibility with several iPhone models in the process. From May 5, 2025, WhatsApp will no longer be compatible with iPhone 5s, iPhone 6, and iPhone 6 Plus models. Users with those devices won't be able to access the encrypted chat service after the specified date unless they ...
iPhone 17 Pro Dual Tone Rectangle Feature 1

iPhone 17 Pro Already Rumored to Have These 8 New Features

Wednesday November 27, 2024 12:19 pm PST by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch for 10 more months, there are already plenty of rumors about the devices. An imaginative iPhone 17 Pro concept based on rumors Below, we recap key changes rumored for the iPhone 17 Pro models so far: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro ...
Apple AI Command Center Concept Mock 3

Apple Expected to Launch This All-New Device Next Year

Wednesday November 27, 2024 1:05 pm PST by
Apple is expected to kick off 2025 by launching an all-new smart home hub, also referred to as a "command center," as early as March. The hub is expected to feature around a six-inch display that can be attached to a tabletop base with a speaker, or mounted on a wall. The device is said to run a new "homeOS" operating system with a customizable widget-focused home screen, and it is expected...
maxresdefault

The MacRumors Show: iPhone 17 Designs Revealed!

Friday November 29, 2024 9:34 am PST by
On this week's episode of The MacRumors Show, we discuss the recently leaked design of the iPhone 17 "Air" and iPhone 17 Pro. Subscribe to The MacRumors Show YouTube channel for more videos Earlier this week, a report from The Information's Wayne Ma revealed that the iPhone 17 Air will have a thickness of between 5mm and 6mm, which would make it the thinnest iPhone ever. In comparison, iPhone ...
airpods pro 2 gradient

AirPods Pro 3 Expected Next Year: Here's What We Know

Thursday November 28, 2024 3:30 am PST by
Despite being released over two years ago, Apple's AirPods Pro 2 continue to dominate the wireless earbud market. However, with the AirPods Pro 3 expected to launch sometime in 2025, anyone thinking of buying Apple's premium earbuds may be wondering if the next generation is worth holding out for. Apart from their audio and noise-canceling performance, which are generally regarded as...
Cyber Monday Deals Feature 2022

Apple Cyber Week Deals Available Now: AirPods, iPads, and More

Sunday December 1, 2024 7:52 am PST by
Although Black Friday has ended, Cyber Week is here and you can find great deals on numerous Apple devices right now. This includes big savings on AirPods, Apple Watch, MacBook Air, iPad, and more. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. Specifically,...

Top Rated Comments

drinkingtea Avatar
66 months ago
I love my iPhone.
Score: 28 Votes (Like | Disagree)
Mr. Awesome Avatar
66 months ago
And people still say Android is better...
Score: 26 Votes (Like | Disagree)
LeeW Avatar
66 months ago
Google - "Yeah whatever, whoever you are, your app is out there"

Apple - "Yeah, register, prove who you are, let us check the app before it gets released, Nah buggy and a resource hog, fix it, ok done, fine it's available on the store"

Android users - but I get a really open app store and can download anything I want, apple store is ****.
Apple users - I saw you in the shower last night.
Score: 24 Votes (Like | Disagree)
iamgalt Avatar
66 months ago
"security flaw"

Yeah, right. On a Google OS?
Score: 20 Votes (Like | Disagree)
osx86 Avatar
66 months ago
Another day, another major Android OS security flaw. But thats not even the real problem. The real issue is that most android phones wont get the proper updates to fix it, leaving millions permanently vulnerable.
Score: 20 Votes (Like | Disagree)
edgonzalez32 Avatar
66 months ago
The amount of people quick to **** on Android is absolutely ridiculous. Ya'll really need to chill with that ****. Yes, it's a major security flaw.

The article also states that Google already pushed out an update to patch the issue. As for other manufacturers putting out a fix, we already know carriers play a role in how fast can get patch updates for Android.

I'm a long time iOS user, was on a Pixel 2 for a year and a half. You know why? Because it's a great phone. And Android is a fantastic platform that can do A LOT of things better than iOS can. At least with an Android, you don't feel like you're using a device in a way the manufacturer wants you to, which is my biggest criticism of iOS as both a user and a UX Designer.

This crapping all over Android is absolutely ridiculous, especially in the forums on this site. Competition is good for both iOS and Android users. And Android does offer a ton of that. It makes both platforms better and gives users more choice. Don't sit here and try to act like you're above people that choose a platform that isn't the one you chose. Because it doesn't satisfy your needs doesn't mean it fails for someone else. You don't know their workflows, use cases, etc.
Score: 16 Votes (Like | Disagree)