var _hmt = _hmt || ;
var hm = document.createElement("script");
hm.src = "https://hm.baidu.com/hm.js?d387e539c1f2d34f09a9afbac8032280";
var s = document.getElementsByTagName("script");
InformationWeek is part of the Informa Tech Division of Informa PLC
This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.
Google: QuadRooter Threat Blocked On Most Android Devices
Google has confirmed that a feature called Verify Apps, built into Google Play Services, is intended to safeguard Android devices from the QuadRooter security threat.
7 Cyber-Security Skills In High Demand
(Click image for larger view and slideshow.)
Android users had a major security scare this week. A set of four security vulnerabilities was reported to leave 900 million Android smartphones and tablets vulnerable to hackers.
8号彩票注册网址A team of mobile researchers at security firm Check Point initially and dubbed it "QuadRooter." It affects Android devices equipped with Qualcomm chipsets, which power popular devices, including three Google Nexus models and the Samsung Galaxy S7.
Hackers who wanted to exploit one of these vulnerabilities could assume total control over the victim's device. All they would have to do is trick an unsuspecting user into downloading a mobile app, through which they could achieve root access.
Naturally, the potential danger of QuadRooter was of concern to consumers and businesses. Sensitive corporate data, video and audio recordings, and capabilities such as GPS tracking could be accessed in a successful breach.
8号彩票注册网址At the time QuadRooter was reported, a Qualcomm spokesperson stated the company had addressed all flaws and provided patches to the open-source community by the end of July, .
Most fixes were delivered via Android monthly security updates, which Google delivers for its Nexus product lineup. Three flaws were addressed in the latest batch of fixes. A delayed final patch will arrive in an upcoming Android update reported to arrive at the beginning of September.
But Google has confirmed Android users may be safer than they originally thought. A feature called Verify Apps is designed to protect them from the QuadRooter threat.
8号彩票注册网址Verify Apps, which is built into Google Play Services, was enabled by default as part of the Android 4.2 Jelly Bean launch nearly four years ago. The feature was created to discover and block the type of attacks enabled by QuadRooter, Google .
"Exploitation of these issues depends on users also downloading and installing malicious applications," a Google spokesperson told Android Central. "Our Verify Apps and SafetyNet protections help identify, block, and remove applications that exploit vulnerabilities like these."
8号彩票注册网址It's important to note devices are technically vulnerable even if Verify Apps is on, the report stated. However, users would have to manually disable another security feature to allow hackers to gain access.
8号彩票注册网址The type of attack conducted via QuadRooter is serious enough for Verify Apps to completely block before installation can begin. Users would see an alert stating "Installation has been blocked" rather than a message of "Installing this app may harm your device," which would give the option to proceed.
All versions of Android following Android 4.2 Jelly Bean with Google Play Services are equipped with Verify Apps. This means more than 90% of devices actively running Android should be protected from the dangers of QuadRooter.
8号彩票注册网址Older versions of Android, dating back to the 2010 release of Android Gingerbread, also have the Verify Apps feature. If you're using an older edition of the OS, you'll have to enable the protection by going to Settings > Security.
This means the QuadRooter vulnerability will likely affect far fewer than 900 million devices -- with 90% of smartphones and tablets being automatically protected from the threat and the other 10% being able to manually enable the protection.
Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
The Cloud Gets Ready for the 20'sThis IT Trend Report explores how cloud computing is being shaped for the next phase in its maturation. It will help enterprise IT decision makers and business leaders understand some of the key trends reflected emerging cloud concepts and technologies, and in enterprise cloud usage patterns. Get it today!