With more than a billion users around the globe, Android is the number one mobile operating system on the market. However, its particular design and the lack of clear rules among Google, manufacturers, and carriers cause a true security crisis. The latest vulnerability report comes from Zimperium, which discovered seven very high-risk bugs. In the worst case, a simple text message would be enough to take over a smartphone.
Android's security crisis
Who wouldn't want to be in charge of a platform like Android? Considering Microsoft's virtual resignation from the mobile space and the current situation of names like Blackberry, I'm sure they would love to be in Google's shoes. But success always finds a way to cause problems, and one of the most frequent in Android is security. Let's review: Technically, Android is an open-source operating system, and thanks to this condition, all kinds of variants and modifications have been developed. Whenever a vulnerability surfaces, both Google and the rest of the community do their best to patch the holes in time... but the chain breaks. Manufacturers and internet service providers have very few incentives to keep devices updated that they think will become obsolete the following year, ignoring the fact that this vision is unsustainable. Bugs accumulate, and the number of affected devices is increasing.
The Stagefright vulnerability
The latest batch of vulnerabilities was reported by Joshua Drake of Zimperium zLabs, and it works as follows: The attacker designs a special text message with a video to exploit errors in Stagefright, the multimedia playback engine used by Android. The video in question is loaded with malicious code, and when the user opens the message... that's it. If multimedia messages are processed through Hangouts, the situation is even worse, since it's not even necessary to open the message, and Drake has even indicated that the infection can take place before hearing the alert of the new message. The good news is that Google has already published fixes. Drake sent the patches to Mountain View in April, and they were validated in less than 48 hours, which partly reveals how serious the vulnerability is.
Patching and its limitations
The bad news is that the vast majority of users will never receive those patches. According to Drake, all versions of Android starting from Froyo 2.2 (inclusive) are affected, and if we go by the frequency of updates published by manufacturers, the percentage of protected users will be 20 percent in the worst case. In even harder numbers, we're talking about 950 million Android devices completely unprotected. HTC said that patches began to be distributed in early July "for its active projects". The people at Silent Circle, developer of the Blackphone, confirmed that their device is up to date with the fixes "for weeks", and T-Mobile basically kicked the ball into the manufacturers' court. To be continued...