ATTENTION: You are viewing a page formatted for mobile devices; to view the full web page, click HERE.

Main Area and Open Discussion > Living Room

Security: Android 5.x Lockscreen Bypass (CVE-2015-3860)

(1/1)

ewemoa:
A vulnerability exists in Android 5.x <= 5.1.1 (before build LMY48M) that allows an attacker to crash the lockscreen and gain full access to a locked device, even if encryption is enabled on the device. By manipulating a sufficiently large string in the password field when the camera app is active an attacker is able to destabilize the lockscreen, causing it to crash to the home screen. At this point arbitrary applications can be run or adb developer access can be enabled to gain full access to the device and expose any data contained therein.

--- End quote ---

via http://sites.utexas.edu/iso/2015/09/15/android-5-lockscreen-bypass/

Navigation

[0] Message Index

Go to full version