PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Researchers Find New Android Stagefright Exploit

Security firm NorthBit estimates that approximately 275 million Android devices could be vulnerable.

 & Stephanie Mlot Contributor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

Remember Stagefright? It's back!

The Metaphor exploit, uncovered by security firm NorthBit, can be used to attack devices running Android 2.2 to 4.0; it also bypasses ASLR on version 5.0 and 5.1. Researchers found the program works best on the Nexus 5 with stock ROM, but phones like the HTC One, LG G3, or Samsung Galaxy S5 are vulnerable with just a few "slight modifications."

Exploit times vary between a few seconds and two minutes; a more sophisticated method reduces those times drastically. In NorthBit's demo (below), the whole process took about 20 seconds.

It's "hard to comprehend how many devices are [potentially] vulnerable," according to Northbit, though the firm puts that number at approximately 275 million.

The researchers say Metaphor simply requires the victim to visit a page containing a malicious MPEG-4 multimedia file—adorable cats, for example. That file then crashes the Android mediaserver, resetting the system. Once rebooted, malicious JavaScript hosted on the site forwards device data to the attacker's server. Meanwhile, the poor sap is still scrolling through furry felines.

Metaphor's server then sends a video file, which exploits the vulnerability and gathers additional information about the device, as ZDNet reported. Another video is then transmitted to the victims' handset, infecting it with malware.

Stagefright debuted in late July, when Zimperium researchers Joshua Drake discovered a bug in Google's mobile operating system that gave hackers access to people's phones just by sending a text.

At the time, about 95 percent of Android devices, or 950 million smartphones, were vulnerable, Drake said. Google and other device manufacturers—including Samsung and LG—in August unleashed a massive software update to combat it.

For more, see There's (Almost) Nothing You Can Do About Stagefright.

About Our Expert

Stephanie Mlot

Stephanie Mlot

Contributor

My Experience

  • B.A. in Journalism & Public Relations with minor in Communications Media from Indiana University of Pennsylvania (IUP)
  • Reporter at The Frederick News-Post (2008-2012)
  • Reporter for PCMag and Geek.com (RIP) (2012-present)

My Areas of Expertise

  • Science & Space
  • Video Streaming Services
  • Social Media
  • Cars & Auto
  • Education

The Tech I Use

  • iPhone 12 Pro
  • MacBook Air (hooked up to a 23-inch Dell monitor)
  • Google Chrome
  • Google Drive
  • Soundcore Life P3 earbuds
  • Various Amazon Echo devices

Read full bio