Definitely, it’s time to spy on Android. Since the beginning of April 2022, articles about malware that can spy on Android smartphone users have proliferated. For example, we remember these 11 apps from the Play Store that can collect GPS data, and even this Russian malware that can read your SMS or eavesdrop on your calls.
We owe the discovery of the day to computer security researchers from Israeli firm Check Point. Indeed, these experts have detected Three critical vulnerabilities in audio decoders of many Qualcomm and MediaTek SoCs. Once these vulnerabilities are exploited, it can act as a springboard to carry out Remote Code Execution (RCE) attacks by simply sending a malicious audio file.
“The impact of an RCE vulnerability can range from executing malware to an attacker who takes control of a user’s media data, including the camera feed of a compromised machine.” explains researchers. They keep going:Additionally, an unprivileged Android app could exploit these vulnerabilities to escalate its privileges and gain access to users’ media data and conversations.
Also read: Android – this malware can block calls to your bank’s customer service
Flaws found in the open source version of Apple Lossless
After review, Check Point experts discovered that its flaws were “rooted” in an audio encoding format originally developed and open-sourced by Apple in 2011. Indeed, this is the Apple Lossless Audio Codec, or ALAC. Lossless data compression of music in digital format.
Qualcomm and MediaTek have integrated the open source version of this codec into their own audio codecs for years. And if Apple has constantly updated the proprietary version of the ALAC codec, this is not the case at all with the open source version. Since it became available on GitHub on October 27, 2011, codec did not benefit from any updates. After explaining the existence of these vulnerabilities to the relevant companies, All three vulnerabilities were fixed by Qualcomm and MediaTek in December 2021.
“The vulnerabilities could be easily exploited. A threat actor could send a song (media file) and inject code into the privileged media service when played by a potential victim. The threat actor may have seen what the smartphone user saw on their phone.” Summing up Check Point researcher Slava Makkaeev.
Source : Hacker News
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

























