'Millions' of Android mobes vulnerable to new Stagefright exploit

Paper lays out how to bypass Google’s ASLR.

Richard Chirgwin

A group of Israeli researchers reckon they’ve cracked the challenge of crafting a reliable exploit for the Stagefright vulnerability that emerged in Android last year.

In a paper [PDF] that’s a cookbook on how to build the exploit for yourself, they suggest millions of unpatched Android devices are vulnerable to their design, which bypasses Android’s security defenses. Visiting a hacker’s webpage is enough to trigger a system compromise, we’re told.

