Researchers ID 'smishing' vulnerability in Android

Nov 05, 2012 by Matt Shipman

(Phys.org)—Mobile security researchers have identified a new vulnerability in popular Android platforms, including Gingerbread, Ice Cream Sandwich and Jelly Bean. The vulnerability has been confirmed by Google, and will be addressed in a future Android release.

Specifically, Xuxian Jiang's research team at NC State has identified an SMS-phishing ("smishing") vulnerability. If an Android user downloads an infected app, the attacking program can make it appear that the user has received an SMS, or text, message from someone on the phone's contact list or from trusted banks. This fake message can solicit personal information, such as passwords for user accounts.

"For responsible disclosure, we will not publish the details of the vulnerability until an ultimate fix is out," Jiang says. "However, we think all recent Android phones are vulnerable."

This video is not supported by your browser at this time.

Pending the release of a fix from Google, Jiang says "users are encouraged to be cautious when downloading and installing apps (particularly from unknown sources). As always, it is important to pay close attention to received SMS text messages, in order to avoid being duped by possible phishing attacks."

Explore further: A new app facilitates number and arithmetic learning in children with special educational needs

More information: A full write-up from Jiang's team is available here: ttp://www.csc.ncsu.edu/faculty/jiang/smishing.html

Related Stories

Apple says it's fixed iPhone SMS vulnerability

Jul 31, 2009

(AP) -- Apple Inc. says it has fixed an iPhone vulnerability that lets hackers knock people offline - and possibly take over the phones - by sending them specially crafted text messages.

Microsoft engineer eyeballs Android botnet

Jul 04, 2012

(Phys.org) -- A Microsoft engineer has spotted a botnet that targets Yahoo! Mail users using Android devices. Terry Zink , who also writes an Internet security blog, said he has evidence of a botnet running ...

Recommended for you

BPG image format judged awesome versus JPEG

Dec 17, 2014

If these three letters could talk, BPG, they would say something like "Farewell, JPEG." Better Portable Graphics (BPG) is a new image format based on HEVC and supported by browsers with a small Javascript ...

Atari's 'E.T.' game joins Smithsonian collection

Dec 15, 2014

One of the "E.T." Atari game cartridges unearthed this year from a heap of garbage buried deep in the New Mexico desert has been added to the video game history collection at the Smithsonian.

User comments : 0

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.