Skip to main content

Researchers find Android vulnerability that can render devices inoperable

android vulnerability mediaserver top 5 best games meek mill bike life siegefall
Image used with permission by copyright holder
Another day, another Android exploit. Just earlier this week, a security researcher disclosed a debilitating flaw in Android multimedia playback tool Stagefright, and now researchers at Trend Micro have discovered a new vulnerability that they claim is potentially just as destructive. According to the firm’s report, an attack leveraging the exploit could, if properly executed, render an Android device “totally silent and non-responsive.”

The vulnerability resides in mediaserver, Android’s background service responsible for indexing videos, pictures, and audio. Trend Micro says that with the right know-how, a hacker could craft a malformed Matroska (usually .mkv) container capable of crashing mediaserver — and the entire operating system, subsequently — when it attempts to process the file. Researcher Wish Wu writes in a blog post that during testing, the exploit affected devices running Android 4.3 and above — about 57 percent of all Android smartphones and tablets by Google’s last count.

Recommended Videos

In its report, Trend Micro envisions increasingly dire scenarios from missed ring tones to permanently locked phones, arising from the exploit. The researchers even theorize a malicious app could render devices inoperable by loading the malformed file at boot. But Google, which was informed of the exploit last week, is a bit more measured. “While our team is monitoring closely for potential exploitation, we’ve seen no evidence of actual exploitation,” a spokesperson told Mashable. “Should there be an actual exploit of this, the only risk to users is temporary disruption to media playback on their device.”

Please enable Javascript to view this content

Ultimately, the vulnerability, while worrisome, isn’t quite as dire as the Stagefright exploit, which allows hackers to hijack and install malware on phones with a simple text message. Still, Google says it’s working on a fix. In the meantime, it suggests that anyone affected by the mediaserver bug try navigating away from the malicious website or uninstalling the misbehaving application.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The OnePlus 13 is coming on January 7 — along with a surprise
The OnePlus logo on the back of the OnePlus Open Apex Edition.

It's official: the OnePlus 13 will launch on January 7, 2025. Preempting the anticipated event by several weeks, OnePlus has officially confirmed the date we’ll see its next major smartphone release outside of China. Additionally, it has revealed some key features and news of a surprise new launch to go along with the phone.

OnePlus will release the OnePlus 13 in three different colors — Black Eclipse, Arctic Dawn, and Midnight Ocean. It’s the latter that is likely to be the model to have, as it is wrapped in a material called micro-fiber vegan leather, which is apparently corrosion and scratch-resistant but still luxurious to the touch. For the Arctic Dawn phone, the glass will have a special coating to give it a silky-smooth finish. It’s likely these are the same colors offered in China, where the phone has already been announced, just with different names.

Read more
I’m really worried about the future of smart glasses
The front of the Ray-Ban Meta smart glasses.

The Ray-Ban Meta smart glasses are among the most interesting, unexpectedly fun, and surprisingly useful wearables I’ve used in 2024. However, as we go into 2025, I’m getting worried about the smart glasses situation.

This isn’t the first time I’ve felt like we’re on the cusp of a new wave of cool smart eyewear products, only to be very disappointed by what came next.
Why the Ray-Ban Meta are so good

Read more
We need to talk about this fantastic, industry-leading Motorola collab
A person holding the Motorola Edge 50 Neo.

We are accustomed to tech brands partnering with adjacent brands, whether it’s OnePlus with Hasselblad or Honor and Huawei with Porsche Design, and often — such as with Xiaomi and Leica — singing the praises of the resulting collaborations. But not enough has been said about Motorola’s now established partnership with color experts Pantone.

It was when the recently released Motorola Edge 50 Neo arrived for me to try out that I finally understood how impactful the collaboration has become. Why? It manages to make even ordinary colors look fantastic.
Boring gray?

Read more