Android Security Flaw Let Apps Access People's Cameras for Secret Video and Audio Recordings

A security flaw in Android smartphones from companies like Google and Samsung allowed malicious apps to record video, take photos, and capture audio, uploading the content to a remote server sans user permission.

The vulnerability was discovered by security firm Checkmarx, and was highlighted today by Ars Technica. The flaw had the potential to leave high-value targets open to having their surroundings illicitly recorded by their smartphones.

androidvulnerability


Android is meant to prevent apps from accessing the camera and the microphone on a smartphone without user permission, but with this particular exploit, an app could use the camera and the microphone to capture video and audio without express user consent. All an app needed to do was get permission to access a device's storage, which is commonly granted as most apps ask for this.

To demonstrate how the flaw worked, Checkmarx created a proof-of-concept app that appeared to be a weather app on the surface but was scooping up copious amounts of data in the background.

The app was able to take pictures and record videos even when the phone's screen was off or the app was closed, as well as access location data from the photos. It was able to operate in stealth mode, eliminating the camera shutter sound, and it could also record two-way phone conversations. All of the data was able to be uploaded to a remote server.

When the exploit was used, the screen of the smartphone being attacked would display the camera when recording video or taking a photo, which would let affected users know what was going on. It could be used secretly when a smartphone display was out of sight or when a device was placed screen down, and there was a feature for using the proximity sensor to determine when a smartphone was facedown.

Google addressed the vulnerability in its Pixel phones through a camera update that was launched back in July, and Samsung has also fixed the vulnerability, though it's not known when. From Google:

"We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure. The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners."

From Samsung:

"Since being notified of this issue by Google, we have subsequently released patches to address all Samsung device models that may be affected. We value our partnership with the Android team that allowed us to identify and address this matter directly."

According to Checkmarx, Google has said that Android phones from other manufacturers could also be vulnerable, so there may still be some devices out there that are open to attack. Google has not disclosed specific makers and models.

Since this is an Android bug, Apple's iOS devices are not affected by the security flaw.

It's not known why apps were able to access the camera without user permission. In an email to Ars Technica, Checkmarx speculated that it could potentially be related to Google's decision to make the camera work with Google Assistant, a feature that other manufacturers may have also implemented.

Top Rated Comments

drinkingtea Avatar
14 months ago
I love my iPhone.
Score: 28 Votes (Like | Disagree)
Mr. Awesome Avatar
14 months ago
And people still say Android is better...
Score: 26 Votes (Like | Disagree)
LeeW Avatar
14 months ago
Google - "Yeah whatever, whoever you are, your app is out there"

Apple - "Yeah, register, prove who you are, let us check the app before it gets released, Nah buggy and a resource hog, fix it, ok done, fine it's available on the store"

Android users - but I get a really open app store and can download anything I want, apple store is ****.
Apple users - I saw you in the shower last night.
Score: 24 Votes (Like | Disagree)
iamgalt Avatar
14 months ago
"security flaw"

Yeah, right. On a Google OS?
Score: 20 Votes (Like | Disagree)
osx86 Avatar
14 months ago
Another day, another major Android OS security flaw. But thats not even the real problem. The real issue is that most android phones wont get the proper updates to fix it, leaving millions permanently vulnerable.
Score: 20 Votes (Like | Disagree)
edgonzalez32 Avatar
14 months ago
The amount of people quick to **** on Android is absolutely ridiculous. Ya'll really need to chill with that ****. Yes, it's a major security flaw.

The article also states that Google already pushed out an update to patch the issue. As for other manufacturers putting out a fix, we already know carriers play a role in how fast can get patch updates for Android.

I'm a long time iOS user, was on a Pixel 2 for a year and a half. You know why? Because it's a great phone. And Android is a fantastic platform that can do A LOT of things better than iOS can. At least with an Android, you don't feel like you're using a device in a way the manufacturer wants you to, which is my biggest criticism of iOS as both a user and a UX Designer.

This crapping all over Android is absolutely ridiculous, especially in the forums on this site. Competition is good for both iOS and Android users. And Android does offer a ton of that. It makes both platforms better and gives users more choice. Don't sit here and try to act like you're above people that choose a platform that isn't the one you chose. Because it doesn't satisfy your needs doesn't mean it fails for someone else. You don't know their workflows, use cases, etc.
Score: 16 Votes (Like | Disagree)

Top Stories

windows 10

Developer Successfully Virtualizes Windows for Arm on M1 Mac

Friday November 27, 2020 7:16 am PST by
Developer Alexander Graf has successfully virtualized the Arm version of Windows on an M1 Mac, proving that the M1 chip is capable of running Microsoft's operating system (via The 8-Bit). Currently, Macs with the M1 chip do not support Windows and there is no Boot Camp feature as there is on Intel Macs, but support for Windows is a feature that many users would like to see. Using the...
iPhone black friday 20 sale feature

Apple Black Friday 2020: Best iPhone Deals

Friday November 27, 2020 12:56 pm PST by
Black Friday is halfway done, but there are still a few deals to shop for on iPhones at carriers like AT&T, Verizon, and T-Mobile/Sprint. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. AT&T Starting with AT&T, you'll find up to $700 off any iPhone 12 when...
AirPods Pro black friday 20 sale feature 2

Black Friday 2020: AirPods Pro Reach Lowest Price Ever [Updated]

Wednesday November 25, 2020 3:22 pm PST by
Black Friday has kicked off this week, and one of the first major sales for the AirPods Pro is available right now on Walmart. You can find this deal below, along with a few other solid discounts on the regular AirPods. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site...
Apple Watc black friday 20 sale feature

Apple Black Friday 2020: Best Apple Watch Deals [Updated]

Wednesday November 25, 2020 4:01 pm PST by
Black Friday sales have begun on a variety of products, including the Apple Watch. There are quite a few deals across the Apple Watch lineup this year, including one of the lowest price we've ever seen the Apple Watch Series 3. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the...
iphone trade in store

UK Environmental Committee Says Apple Contributing to 'Throwaway Culture' of 'Short-Lived Products'

Thursday November 26, 2020 7:07 am PST by
Technology companies like Apple are contributing to e-waste by making their products difficult to repair, and charging expensive repair fees, according to a lengthy report published today by the UK Parliament's Environmental Audit Committee. "We were told that Apple glues and solders parts together on their laptops, which makes repairing them very difficult," the Committee wrote in a summary ...
MacBooks black friday

Apple Black Friday 2020: Best Mac and MacBook Deals

Thursday November 26, 2020 8:29 pm PST by
For Black Friday 2020, many retailers have solid deals on a variety of Macs. Apple's new M1 Macs are ones everyone wants right now, but because they're so new, deals on them are fairly sparse, although we are seeing some modest discounts. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps...
Top Stories 38 Feature

Top Stories: Black Friday Deals, Redesigned MacBooks, Hands-On With Apple's M1 Macs

Saturday November 28, 2020 6:00 am PST by
With Apple's holiday hardware lineup seemingly all set, attention this week turned to the shopping end of things with Apple and other retailers rolling out their Black Friday deals. That wasn't the only news this week, however, as we've continued to learn more about Apple's new M1-based Macs and we've even heard some fresh rumors about redesigned Mac notebooks coming next year, so read on...
General black friday 20 sale feature 2

Apple Black Friday 2020: Our Top Picks

Friday November 27, 2020 6:16 am PST by
Black Friday shopping has officially kicked off across the United States, and we've been collecting the best deals for Apple's iPads, Macs, AirPods, the HomePod, Apple Watch, and more in separate articles. In order to further streamline your Black Friday shopping this year, we've put together this quick list of our top picks of the overall best Apple-related bargains happening today. Note:...
mac mini macbook pro macbook air

Apple M1 Hands-On Comparison: MacBook Air vs. MacBook Pro vs. Mac Mini

Monday November 23, 2020 3:40 pm PST by
Apple's M1 Macs are out in the wild now, but ahead of the holidays, you might still be trying to figure out which one to pick up, either for yourself or as a gift for someone else. We've got all three of the new Macs available, so we thought we'd give MacRumors readers a hands-on overview of each machine in our latest YouTube video. Subscribe to the MacRumors YouTube channel for more videos. ...
General black friday 20 sale feature

Thanksgiving Day Deals Still Available on AirPods, M1 Macs, Apple Watch Series 6, iPads

Thursday November 26, 2020 10:21 am PST by
Black Friday deals seem to start earlier and earlier every year, so there were already a wide variety of discounts available for Apple products on Thanksgiving Day. Many of the deals remain available even after Thanksgiving, but act fast, as inventory quickly fluctuates. Thanksgiving Day Deals on Apple Products — Still Available:AirPods with a wireless charging case remain available for...