Just in:
GitHub Actions reliability falls below enterprise benchmark // Asia Responsible Enterprise Awards and Asia Pacific Enterprise Awards 2026 China Chapter Celebrate Resilient Enterprises Forging Legacies of Excellence and Impact // CodeRabbit secures $143 million for AI governance push // UK fraud filings reach first-half record // Warsh Fed will do nothing to derail rally in US bank shares // Telegram seeks .gram domain for user web identities // allnex Announces the Next SCA Capacity Investment In APAC // Hormuz shipping remains severely curtailed amid tensions // UAE freezes trade and financial dealings with Iran // Employed but stuck: Malaysia’s resilient labour market masks a career mobility gap // Tech Data Expands IBM Distribution to Accelerate Partner-Led Growth Across Asia Pacific // Coming endgame of global macro, AI bubble // Alpro Group and AstraZeneca Collaborate to Advance Early Detection Across the Cardio-Kidney-Metabolic Spectrum and Raise Awareness of Hyperkalemia // tridorian launches Gemini Enterprise Experience Center in Singapore to help enterprises turn AI ambition into business outcomes // At Just 27, Hamdan Bin Turki Al Mehairi Is Building One of the Most Ambitious Business Groups // NASA ground software flaw exposes spacecraft commands // Saudi Arabia raises US Treasury holdings to $142.5bn // Trump rejects Iran truce extension as Lebanon flares // US emergency oil reserve sinks to 1982 low // 10Life Test: Airline Add-On Travel Insurance Priced by Airfare — Same Coverage, Premiums Differ by up to 34% //

Google patches severe Android boot mode vulnerability

1483951674 new locker crypto repents imagecredsymantec

new-locker-crypto-repents-imagecredsymantec.jpg

Symantec

Google has resolved a dangerous Android vulnerability which allowed attackers to reboot Nexus devices into custom boot modes, leading to spying and remote attacks.

Patched as part of Google’s January Android security bulletin, the flaw, CVE-2016-8467, grants cyberattackers the ability to use PC malware or malicious chargers to reboot a Nexus 6 or 6P device and implement a special boot configuration, or boot mode, which instructs Android to turn on various extra USB interfaces.

According to IBM X-Force Application Security Research Team researchers Roee Hay and Michael Goberman, who revealed further details of the vulnerability in a blog post, the flaw gives attackers access to interfaces which offer additional control over a compromised device.

In particular, the Nexus 6 the modem diagnostics interface is of concern as accessing this platform gives attackers access to the modem, which compromises “confidentiality and integrity,” the team says.

Once an attacker has gained access to the modem they can intercept phone calls, for example. It would also be possible to sniff mobile data packets and grab information including GPS coordinates of the device for tracking, place phone calls, steal call information and either access or change nonvolatile (NV) items or the EFS partition of a device.

See also: Google patches Dirty Cow vulnerability in latest Android security update

IBM says that if Android Debug Bridge (ADB) is enabled on the device, PC malware or a malicious charger can boot the target device with the special boot mode configuration. Once connected, the user is forced to accept the PC or charger permanently, a few commands are issued, and the device is rebooted.

“Every future boot from this point forward will have the boot mode configuration enabled,” IBM says. This means the attack is persistent and no longer requires ADB to run, although it still requires USB access.”

“Therefore, the attacker only needs the victim to enable ADB once,” the researchers added. “Moreover, a lucky attacker might wait for the device to be in fastboot mode, which requires no authorization from the victim. This, however, is less likely.”

If attackers have physical access to the device, they can also reboot it into the custom boot mode manually.

These issues are less severe on the Nexus 6P due to firmware protections, however, a quirk in the device type means attackers can open ADB sessions even if the mode has been disabled.

In addition, due to the inclusion of additional USB interfaces in both device types, attackers can also access other interfaces to send or on SMS messages and potentially bypass two-factor authentication, escalate privileges, change radio settings and access a wide range of mobile device features.

Google has now patched the flaw by forbidding a locked bootloader to boot with the dangerous boot modes.

In December, researchers revealed that a new variant of Android malware called Gooligan was exploiting unpatched vulnerabilities to steal sensitive user data.

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Building a Global EV Footprint: How VinFast and Local Partners Power Middle East Expansion // tridorian launches Gemini Enterprise Experience Center in Singapore to help enterprises turn AI ambition into business outcomes // Wiz AI agent exposes Snowflake workflow security gap // 10Life Test: Airline Add-On Travel Insurance Priced by Airfare — Same Coverage, Premiums Differ by up to 34% // Telegram seeks .gram domain for user web identities // GitHub Actions reliability falls below enterprise benchmark // Coming endgame of global macro, AI bubble // NASA ground software flaw exposes spacecraft commands // Aramco offers Asian refiners crude via Fujairah // Dubai tourism recovery gathers pace with flight returns // Tech Data Expands IBM Distribution to Accelerate Partner-Led Growth Across Asia Pacific // At Just 27, Hamdan Bin Turki Al Mehairi Is Building One of the Most Ambitious Business Groups // India pushes coal gasification to reduce import risks // Alpro Group and AstraZeneca Collaborate to Advance Early Detection Across the Cardio-Kidney-Metabolic Spectrum and Raise Awareness of Hyperkalemia // allnex Announces the Next SCA Capacity Investment In APAC // Saudi Arabia raises US Treasury holdings to $142.5bn // Asia Responsible Enterprise Awards and Asia Pacific Enterprise Awards 2026 China Chapter Celebrate Resilient Enterprises Forging Legacies of Excellence and Impact // US oil reserve sinks towards four-decade low // UAE freezes trade and financial dealings with Iran // Rupee weakens as oil and geopolitical risks mount //