Mac Developer: Critical Qualcomm security bug leaves many phones open to attack | Ars Technica
Critical Qualcomm security bug leaves many phones open to attack | Ars Technica: "The flaw, which is most severe in Android versions 4.3 and earlier, allows low-privileged apps to access sensitive data that's supposed to be off-limits, according to a blog post published by security firm FireEye. But instead, the data is available by invoking permissions that are already requested by millions of apps available in Google Play. Company researchers said the vulnerability can also be exploited by adversaries who gain physical access to an unlocked handset. Indexed as CVE-2016-2060, the bug was first introduced when mobile chipmaker Qualcomm released a set of programming interfaces for a system service known as the 'network_manager' and later the 'netd' daemon."
On a day when it sucks to be an Android user.
Labels: android vs. ios