Unless you Upgrade to Android Pie, a Vulnerability Leaves your Phone Trackable -- and Google Won't Fix It
A vulnerability in the Android operating system means that it is worryingly easy to track and locate phones. While the issue has been addressed in Android Pie, Google has no plans to patch the vulnerability in earlier versions of its mobile OS.
The vulnerability (CVE-2018-9489) was revealed in a report from Nightwatch Cybersecurity which warns that it can be used to "uniquely identify and track any Android device" and also to "geolocate users". As well as Google's own Android builds, the problem is also said to affect forked versions such as FireOS.
The vulnerability, which was first reported to Google back in March, means that it is possible for apps to bypass permissions and gain access to information that is contained in system broadcasts -- information that can be very revealing. The problem is made all the more serious thanks to the fact that the vast majority of people will never see Pie on their phones, meaning their handsets will remain vulnerable.
Describing the problem, Nightwatch Cybersecurity says:
System broadcasts by Android OS expose information about the user's device to all applications running on the device. This includes the WiFi network name, BSSID, local IP addresses, DNS server information and the MAC address. Some of this information (MAC address) is no longer available via APIs on Android 6 and higher, and extra permissions are normally required to access the rest of this information. However, by listening to these broadcasts, any application on the device can capture this information thus bypassing any permission checks and existing mitigations.
Because MAC addresses do not change and are tied to hardware, this can be used to uniquely identify and track any Android device even when MAC address randomization is used. The network name and BSSID can be used to geolocate users via a lookup against a database of BSSID such as WiGLE or SkyHook. Other networking information can be used by rogue apps to further explore and attack the local WiFi network.
It is not known whether the vulnerability has been exploited in the wild, but now it has been exposed, that risk has greatly increased. More information about the security issue can be found in the Nightwatch Cybersecurity report.
- M&E Project Manager
- £35,000 - £65,000 + Bonus + Benefits
M&E Project Manager with a Data centre / Construction / Mission Crticial background is needed in London area to join a leading Data Centre business. The M&E Project Manager MUST have experience working in data centre or mission critical project environments for a minimum of 2 years The M&E Project Manager will be responsible for planning, controlling and coordinating the delivery of various construction and business as usual projects. Ensuring work keeps to deadlines and within cost parameters. You will be responsible for overseeing projects worth over £5 million from start to finish, managing suppliers and contractors. This is an excellent opportunity for someone looking to build a career working for an internationally recoginised brand who truely belive in staff development and progression. Reference Number: PG7448
- Marketing Specialist
- £35k - £37k + Bonus + Excellent Benefits
My client, a leading name in the IT industry, are seeking a Marketing Specialist to join their team. This is an excellent role for someone looking to develop themselves in a diverse role with resposnbilites and authority with the real chance to make change and have an effect on a global business. Required Experience: 5+ Years in Marketing + Public Relations Experience organising and running campaigns and events. Content Creation - Social Media, Website and Blogs Email Campaigns A degree in Marketing, Business admin or related subject Marketing qualification, ideally CIM. IT / Telecoms Background prefered but not essential. Reference: PG7447
- ServiceNow Administrator (Contract)
- £350 Per Day
We are currently working on behalf of a London based service provider who are on the look out for a ServiceNow Administrator for a 6 month initial contract The ServiceNow Administrator will be responsible for supporting, configuring, scripting & integrating the ServiceNow ITSM (IT Service Management) tool. Requirements Current ServiceNow ITSM (IT Service Management) experience is a MUST Current experience within an IT service provider A Certified ServiceNow System Administrator certification isn’t a must be extremely beneficial Day Rate: £350 Per Day Reference Number: BD7439a
- Cyber Security Sales
- £120,000 – £140,000 OTE
£120k - £140k OTE Sales Account Management / New Business in the London / Reading area. This opportunity comes with existing accounts with internal sales support. MUST have the ability to develop New business as well as help existing accounts. Experience selling Solution and Managed service experience preferred e.g. Check Point, Palo Alto, F5, etc. Must be UK based and ideally able to achieve SC clearance DCL Search & Selection Exclusive and looking to hire ASAP. Contact me for more info 07884666351 / chris.holt@DCLSearch.com Reference Number: CH7444