Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Google says most users 'protected' against 'Quadrooter' Play Store should spot exploits
The Register UK ^ | 10 August 2016, 2:28pm | By Richard Chirgwin

Posted on 08/11/2016 2:30:21 AM PDT by Swordmaker

The “Quadrooter” vulnerabilities in Qualcomm-based Android phones might grant total control over target devices, but Google reckons attacks should hardly ever reach users.

The Chocolate Factory reckons the Verify Apps feature in its Play Store was already blocking apps that tried to take advantage of Quadrooter.

Only a reckless user would be compromised in the first place, since you'd have to download a compromised app from a non-Google source – and that's where Verify Apps comes in.

Google pointed out to Android Central that the four-year-old feature, along with its SafetyNet, was designed to protect users from non-Play Store malice.

Instead of a “this file may harm you”, Verify Apps should completely block an app trying to exploit Quadrooter, Google says – and since that feature protects everything from Android 4.2 onwards, by Google's Android population data, more than 90 per cent of devices out there are protected.

When Checkpoint first announced Quadrooter, Square's Dino Dai Zovi said Verify Apps would probably protect users against the attack.

Only one of the vulnerabilities, CVE-2016-5340, remains unpatched in current Androids (if you're lucky enough to get prompt updates): “The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.”

Google says it will have that one patched soon.

Sponsored: Global DDoS threat landscape report


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: android; quadrooter; security

1 posted on 08/11/2016 2:30:22 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: dayglored; ThunderSleeps; ShadowAce

Pinging for Google’s comments on Quadrooter.


2 posted on 08/11/2016 2:31:50 AM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Well, if they’re telling the truth that’s that.


3 posted on 08/11/2016 4:07:32 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

This article is written in a parallel language.


4 posted on 08/11/2016 4:27:21 AM PDT by abclily
[ Post Reply | Private Reply | To 1 | View Replies]

To: 109ACS; aimhigh; bajabaja; Bikkuri; Bobalu; Bookwoman; Bullish; Carpe Cerevisi; DarthDilbert; ...
Update on "Quadrooter" - ANDROID PING!

Android Ping!
If you want on or off the Android Ping List, Freepmail me.

5 posted on 08/11/2016 5:33:06 AM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

Android with a huge security hole, Microsoft accidently leaking the master key, but people still whine that apple keeps too tight control of their eco system. Heh.


6 posted on 08/11/2016 8:26:19 AM PDT by TalonDJ
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson