Now it’s more important than ever to update your phone.
Check Point security has found a vulnerability in mobile devices that run Android, which allows credit card details to be accessed by hackers.
Mobile operating systems like Android offer a Rich Execution Environment (REE), providing a hugely extensive and versatile runtime environment, which allows apps to run on the device. However, while bringing flexibility and capability, REE leaves devices vulnerable to a wide range of security threats. A Trusted Execution Environment (TEE) is designed to reside alongside the REE and provide a safe area on the device to protect assets and to execute trusted code. Qualcomm makes use of a secure virtual processor, which is often referred to as the “secure world”, in comparison to the “non-secure world”, where REE resides.
But Check Point “fuzzed” a “hole” into this secure world
In a 4-month research project, Check Point researchers attempted and succeeded to reverse Qualcomm’s “Secure World” operating system. Check Point researchers leveraged a “fuzzing” technique to expose the hole. Fuzz testing (fuzzing) is a quality assurance technique used to discover coding errors and security loopholes in software, operating systems or networks. It involves inputting massive amounts of random data, called fuzz, to the test subject in an attempt to make it crash.
Check Point implemented a custom-made fuzzing tool, which tested trusted code on Samsung, LG, and Motorola devices. Through fuzzing, Check Point found 4 vulnerabilities in trusted code implemented by Samsung (including S10), 1 in Motorola, 1 in LG, but all code sourced by Qualcomm itself. To address the vulnerability, the runtime of Android needs to be protected from both attackers and users. This is typically achieved by moving the secure storage software to a hardware-supported TEE.
Check Point Research disclosed its findings directly to the companies and gave them time to patch vulnerabilities. Samsung patched three vulnerabilities and LG patched one. Motorola and Qualcomm responded, but have yet to provide a patch, and there is no confirmation of a release date yet.
Check Point Research has urged mobile phone users to stay vigilant and check their credit and debit card providers for any unusual activity. In the meantime, they are working with the vendors mentioned to issue patches.