Android FakeID Vulnerability Walkthrough
1,375 views · Published 19 March 2015 · 29:49 · Indexed 20 September 2026
Channel: Black Hat · 2015 · People & Blogs
By Jeff Forristal "The team that discovered the Android MasterKey vulnerability in 2013 is here to present another new Android vulnerability with widespread impact: a flaw in Android application handling, allowing malicious applications to escape the normal application sandbox and get special security privileges without any user notification. This can lead to a malicious application having the ability to steal user data, recover passwords and secrets, or in certain cases, compromise the whole Android device. The vulnerability is embedded in all shipped Android devices since January 2010 (Android Eclair 2.1). This presentation aims to: walk through the technical root cause of this responsibly disclosed vulnerability (Google bug 13678484), explain why it's a problem, show how an attacker would create an exploit for it, and finally demonstrate the exploit against a live device. The presentation will also coincide with the release of a free security scanning tool to help end-users scan for risk of this vulnerability on their end devices."
More from this channel
-
1:00:09
Black Hat USA 2000 - Advanced Windows NT/2K Security (II)
-
1:25:19
Black Hat USA 2003 - The Law of Vulnerabilities
-
58:34
Black Hat USA 2012 - A Stitch in Time Saves Nine: A Case of Multiple Operating System Vulnerability
-
1:01:51
Black Hat USA 2005 - Rogue Squadron: Evil Twins, 802.11intel, Radical RADIUS, & Weaponry for Windows
-
50:45
Black Hat USA 2012 - The Info Leak Era on Software Exploitation
-
1:19:53
Black Hat USA 2002 - Security Aspects in Java Bytecode Engineering
-
49:27
Black Hat Asia 2014 - Persist It: Using and Abusing Microsoft's Fix It Patches
-
28:11
Resurrecting The Read_Logs Permission on Samsung Devices