Android: Apple codec vulnerability


Security experts from Check Point Research report a security vulnerability in Android devices, namely those with the commonly used chipsets from Qualcomm and MediaTek. The background is their use of older versions of the Apple Lossless Audio Codec (ALAC) – from the main competitor Apple. As a result, there is a risk of data theft on many Android devices, the infiltration of malware or even external control of the device. According to the researchers, around two-thirds of all Android devices sold in 2021 were affected. Quite a few smartphones are still at risk.

The best antivirus

test winner



Bitdefender

Norton 360 Premium


NortonLifeLock

Avast One


Avast

Avira Prime


Avira

G Data Total Security


GData

Kaspersky Total Security


test grade

2.5

satisfactory

Kaspersky

Windows Defender


test grade

3.1

satisfactory

Microsoft

Eset Smart Security Premium


eset

Complete list: The best antivirus

ALHACK: Android threat from Apple software

Apple released the source code of the lossless audio codec in 2011, but then kept programmed security updates to itself. Third parties such as MediaTek and Qualcomm apparently used the old version of the software on Android, which was afflicted with security vulnerabilities, for a long time without revising the ALAC code itself. This made it possible for attackers to remotely execute malicious code on an Android target device if the user played a correspondingly manipulated audio file on it. The security researchers dubbed this attack “ALHACK”.

The best smartphones with Android 11

8 pers


OnePlus

8T


OnePlus

Find X2 Pro


OPPO

11T


xiaomi

11T Pro


xiaomi

X60 Pro


Vivo Mobiles

ROG Phone 5


Asus

Xperia 1 III


Sony

Complete list: The best smartphones with Android 11

In order to avert the danger, the two chipset manufacturers released patches after the problem became known at the end of 2021, which were released for affected devices with the December security updates for Android at the latest. Unfortunately, there are still many Android devices in circulation that already stopped receiving security updates in December 2021. Are you still using an older device? Then consider buying a new one, and until then, be especially suspicious of stranger’s audio files.



Source link -62