Elevation of Privilege Vulnerability Could Bypass "Screen Lock" Of Android 5.0 Within 5 minutes

A Security researcher and hacker, named John Gordon, has found an easy way to bypass the security of locked smartphones running Android 5.0 and 5.1 (Build LMY48M).

Many of us use various security locks on our devices like Pattern lock, PIN lock and Password lock in order to protect the privacy of our devices.

The vulnerability, assigned CVE-2015-3860, has been dubbed as "Elevation of Privilege Vulnerability in Lockscreen".

Attack scenario:
  1. Open the Emergency dialer screen.
  2. Type a long string of numbers or special characters in the input field untill limit exhausts.Don't forget to copy the long string ,coz it will work as a master key.
  3. Now Open camera application and click on setting icon found in notification bar without closing the camera application
  4. Now, it will ask to the input the password, paste the earlier copied continuously to the input field of the password, to create an even larger string.
  5. Come back to camera and divert yourself towards clicking photos or volume button with simultaneously tapping the password input field.


As and when the camera application will get crashed by the above process attacker may access your device without password.

For more details,Watch the video demonstration given below, 


Comments

Popular posts from this blog

Location.Hash exploit || JQuery 1.11.3/1.7.2/1.6.1 Cross Site Scripting

JQuery UI 1.11.4 Cross Site Scripting

Bypass Mod_Security