Technology
Forget Pegasus, camera on your Android phone can spy on you
New Delhi, Nov 21
WhatsApp snooping via Israeli spyware Pegasus has shown smartphones have become new-age surveillance tools and now, security researchers have identified that selfie camera in your smartphone can easily spy on you.
According to Erez Yalon and Pedro Umbelino, security researchers at cyber security firm Checkmarx, they have found vulnerabilities impact the camera apps of smartphone vendors like Google Pixel and some Samsung devices in the Android ecosystem, presenting significant implications to hundreds-of-millions of smartphone users.
Both Google and Samsung have issued a security patch for the vulnerabilities.
"Having a Google Pixel 2 XL and Pixel 3 on-hand, our team began researching the Google Camera app, ultimately finding multiple concerning vulnerabilities stemming from permission bypass issues," said Yalon.
After further digging, they found that these same vulnerabilities impact the camera apps of other smartphone vendors in the Android ecosystem - namely Samsung.
After a detailed analysis of the Google Camera app, the team found that by manipulating specific actions and intents, an attacker can control the app to take photos and/or record videos through a rogue application that has no permissions to do so.
Additionally, they found that certain attack scenarios enable malicious actors to circumvent various storage permission policies, giving them access to stored videos and photos, "as well as GPS metadata embedded in photos, to locate the user by taking a photo or video".
It is known that Android camera applications usually store their photos and videos on the SD card. Since photos and videos are sensitive user information, in order for an application to access them, it needs special permissions: storage permissions.
"Unfortunately, storage permissions are very broad and these permissions give access to the entire SD card. There are a large number of applications, with legitimate use-cases, that request access to this storage, yet have no special interest in photos or videos," said the researchers.
It means that a rogue application can take photos and/or videos without specific camera permissions, and it only needs storage permissions to take things a step further and fetch photos and videos after being taken.
Additionally, if the location is enabled in the camera app, the rogue application also has a way to access the current GPS position of the phone and user.
Google said that "We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure.
"The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners," the company said.
Samsung has also patched the vulnerability, said the researchers.
According to Erez Yalon and Pedro Umbelino, security researchers at cyber security firm Checkmarx, they have found vulnerabilities impact the camera apps of smartphone vendors like Google Pixel and some Samsung devices in the Android ecosystem, presenting significant implications to hundreds-of-millions of smartphone users.
Both Google and Samsung have issued a security patch for the vulnerabilities.
"Having a Google Pixel 2 XL and Pixel 3 on-hand, our team began researching the Google Camera app, ultimately finding multiple concerning vulnerabilities stemming from permission bypass issues," said Yalon.
After further digging, they found that these same vulnerabilities impact the camera apps of other smartphone vendors in the Android ecosystem - namely Samsung.
After a detailed analysis of the Google Camera app, the team found that by manipulating specific actions and intents, an attacker can control the app to take photos and/or record videos through a rogue application that has no permissions to do so.
Additionally, they found that certain attack scenarios enable malicious actors to circumvent various storage permission policies, giving them access to stored videos and photos, "as well as GPS metadata embedded in photos, to locate the user by taking a photo or video".
It is known that Android camera applications usually store their photos and videos on the SD card. Since photos and videos are sensitive user information, in order for an application to access them, it needs special permissions: storage permissions.
"Unfortunately, storage permissions are very broad and these permissions give access to the entire SD card. There are a large number of applications, with legitimate use-cases, that request access to this storage, yet have no special interest in photos or videos," said the researchers.
It means that a rogue application can take photos and/or videos without specific camera permissions, and it only needs storage permissions to take things a step further and fetch photos and videos after being taken.
Additionally, if the location is enabled in the camera app, the rogue application also has a way to access the current GPS position of the phone and user.
Google said that "We appreciate Checkmarx bringing this to our attention and working with Google and Android partners to coordinate disclosure.
"The issue was addressed on impacted Google devices via a Play Store update to the Google Camera Application in July 2019. A patch has also been made available to all partners," the company said.
Samsung has also patched the vulnerability, said the researchers.
4 hours ago
Piyush Goyal meets Canadian Minister Maninder Sidhu to seal trade pact soon
5 hours ago
Marathi film ‘Gondhal’ announced as India's official selection for 99th Academy Awards
5 hours ago
Friendship Cup a celebration of cricket, reflects strong India-Afghanistan bond: DDCA chief Jaitley
8 hours ago
ActBlue faces scrutiny over foreign donations
8 hours ago
Kwatra recalls leadership lesson from mentorship under Satya Nadella’s father
10 hours ago
Zee TV’s Sa Re Ga Ma Pa – The Original Icon of Singing Shows is Back with Its Grandest Season Yet; Will Also Stream on ZEE5
10 hours ago
Lust Stories 3 Review: Four Stories. Unusual Desires and Plenty of Surprises
10 hours ago
Joey King: Sandra Bullock's one of the nicest people I’ve ever met in my life
10 hours ago
Upendra’s first look from Teja Sajja's 'Zombie Reddy2 NXT LVL' released!
10 hours ago
Karan Johar and Varun Dhawan to host IIFA Awards 2027 in Abu Dhabi
10 hours ago
Sana Thampi opens up about her first collaboration with Kiran Rao for ‘Lust Stories 3’
10 hours ago
Nivin Pauly pens note of gratitude as his Bethlehem Kudumba Unit's collections go past the Rs 300 crore mark!
10 hours ago
Actor Nani on why he does not want people to call his films pan-Indian!
