Bug in Qualcomm mobile chip puts Android users' privacy at risk

Source From: IANS 2021-05-08 14:44:21

Cyber security researchers have discovered a high-risk security vulnerability in Qualcomm mobile chip responsible for cellular communication in nearly 40 per cent of the high-end phones offered by Google, Samsung, LG, Xiaomi and OnePlus.

If exploited, the vulnerability in Qualcomm mobile station modem (MSM) would have allowed an attacker to use Android OS itself as an entry point to inject malicious and invisible code into phones, granting them access to SMS messages and audio of phone conversations, according to Check Point Research.

Vulnerability also could have potentially allowed an attacker to unlock a mobile device's SIM, according to the cyber security company.

Qualcomm has confirmed the bug and fixed the issue and mobile players are notified, according to the researchers.

The chip-maker classified the high-rated vulnerability as CVE-2020-11292, notifying the relevant device vendors.

Qualcomm provides a wide variety of chips that are embedded into devices that make up over 40 per cent of the mobile phone market.

According to Counterpoint Research, Qualcomm's Mobile Station Modem is a system of chips that provides capabilities for things like voice, SMS, and high-definition recording, mostly on higher-end devices.

"Phone-makers can customise the chips so they do additional things like handle SIM unlock requests. The chips run in 31 per cent of the world's smartphones", according to figures from Counterpoint Research.

The Check Point team found that if a security researcher want to implement a modem debugger to explore the latest 5G code, the easiest way to do that is to exploit MSM data services through QMI so could a cybercriminal, of course.

"During our investigation, we discovered a vulnerability in a modem data service that can be used to control the modem and dynamically patch it from the application processor," they said in a blog post on Thursday.