Security issue altered in Qualcomm mobile chip modems
By MYBRANDBOOK
Cyber security researchers have discovered a high-risk security vulnerability in Qualcomm mobile chip responsible for cellular communication in nearly 40 per cent of the high-end phones offered by Google, Samsung, LG, Xiaomi and OnePlus.
According to CheckPoint Research, if exploited, the vulnerability in Qualcomm mobile station modem (MSM) would have allowed an attacker to use Android OS itself as an entry point to inject malicious and invisible code into phones, granting them access to SMS messages and audio of phone conversations. Vulnerability also could have potentially allowed an attacker to unlock a mobile device's SIM.
Qualcomm has confirmed the bug and fixed the issue and mobile players are notified. The chip-maker classified the high-rated vulnerability as CVE-2020-11292, notifying the relevant device vendors. Qualcomm provides a wide variety of chips that are embedded into devices that make up over 40 per cent of the mobile phone market.
According to Counterpoint Research, Qualcomm's Mobile Station Modem is a system of chips that provides capabilities for things like voice, SMS, and high-definition recording, mostly on higher-end devices.
The Check Point team found that if a security researcher wanted to implement a modem debugger to explore the latest 5G code, the easiest way to do that is to exploit MSM data services through QMI so could a cybercriminal, of course.
In a blog post they said, "During our investigation, we discovered a vulnerability in a modem data service that can be used to control the modem and dynamically patch it from the application processor. This means an attacker could have used this vulnerability to inject malicious code into the modem from Android, giving them access to the device user's call history and SMS, as well as the ability to listen to the device user's conversations.”
A hacker can also exploit the vulnerability to unlock the device's SIM, thereby overcoming the limitations imposed by service providers on it.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
CENTRE FOR DEVELOPMENT OF TELEMATICS (C-DOT)
TAC SECURITY SOLUTIONS
DELL TECHNOLOGIES INDIA PVT. LTD.
MICROTEK INTERNATIONAL PVT. LTD.
Icons Of India : Debjani Ghosh
Debjani Ghosh is the President of the National Association of Software...
Icons Of India : Girish Mathrubootham
Girish Mathrubootham is the Founder of Freshworks (previously known ...
Icons Of India : MADHABI PURI BUCH
Madhabi Puri Buch is the first-female chairperson of India’s markets...
NPCI - National Payments Corporation of India
NPCI is an umbrella organization for operating retail payments and set...
C-DAC - Centre for Development of Advanced Computing
C-DAC is uniquely positioned in the field of advanced computing...
NSE - National Stock Exchange
NSE is the leading stock exchange in India....
Indian Tech Talent Excelling The Tech World - Lal Karsanbhai, President & CEO, Emerson
Lal Karsanbhai, President and CEO of Emerson, assumed the leadership i...
Indian Tech Talent Excelling The Tech World - Thomas Kurian, CEO- Google Cloud
Thomas Kurian, the CEO of Google Cloud, has been instrumental in expan...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...