In-depth

Google patches Nexus bug that lets hackers steal data from locked devices

IBM’s security team found the Nexus 5X glitch after discovering a bypass hole

Google has patched a security bug in its Nexus 5X smartphones that could have exposed sensitive user data stored on handsets, even if they were locked.

IBM's security team found the Nexus 5X glitch after discovering a bypass hole that could allow hackers to dump memory from locked phones via a bootloader problem that could also facilitate wholesale memory dumps via USB, such as a charger.

Advertisement - Article continues below

IBM X-Force research lead Roee Hay said exploiting the flaw was simple and only required a device to be put into fastboot mode.

"A vulnerability in Nexus 5X's bootloader allows an attacker to obtain a full memory dump of the device," said Hay. "The vulnerability can be exploited by physical attackers or by non-physical ones having Android Debug Bridge [ADB] access to the device."

One possible scenario where a non-physical attacker can get ADB access is by first targeting an ADB-authorised developer's PC and infecting it with malware, the IBM researchers said.

Another way is by using malicious chargers targeting ADB-enabled devices. "Using such chargers requires the victim to authorise the charger once connected," the IBM team said.

In this instance, the victim is a Nexus 5X user with Android 6.0 MDA39E through 6.0.1. In order to achieve a successful attack, the attacker needs to reboot the phone into the well-known fastboot' mode, which can be done without any authentication.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"A physical attacker can do this by pressing the Volume Down' button during device boot," said IBM Security Intelligence. "An attacker with ADB access can do this by issuing the adb reboot bootloader' command. The fastboot mode exposes a USB interface, which on locked devices must not allow any security sensitive operation to be commanded."

However, what IBM discovered was that if the attacker issued the fastboot oem panic' command via the fastboot USB interface, the bootloader would be forced to crash.

The research team explained that such a crash caused the bootloader to expose a serial-over-USB connection, which allowed them to fetch a full memory dump of the device, using tools such as QPST Configuration. They were then able to expose the users' personal data.

Luckily, Google has patched the security bug since IBM's discovery. To make sure your device is safe from the attack, visit the Google website and download the most up to date Nexus software option.

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Putting a spotlight on cyber security

An examination of the current cyber security landscape

Download now

The economics of infrastructure scalability

Find the most cost-effective and least risky way to scale

Download now

IT operations overload hinders digital transformation

Clearing the path towards a modernised system of agreement

Download now
Advertisement

Recommended

Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
Visit/cloud/cloud-security/356288/csa-and-issa-form-cybersecurity-partnership
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020
Visit/business/policy-legislation/356215/senators-propose-a-bill-aimed-at-ending-warrant-proof-encryption
Policy & legislation

Senators propose a bill aimed at ending warrant-proof encryption

24 Jun 2020

Most Popular

Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/policy-legislation/data-protection/356344/eu-institutions-warned-against-purchasing-any-further
data protection

EU institutions told to avoid Microsoft software after licence spat

3 Jul 2020
Visit/mobile/mobile-phones/356335/the-man-has-ruined-my-huawei-p40
Mobile Phones

The Man has ruined my Huawei P40

3 Jul 2020