Vulnerabilities / Threats
7/2/2013
11:36 AM
Connect Directly
RSS
E-Mail
50%
50%

Skype Bug Enables Android Lock Screen Bypass

Up to half a billion Android devices that have Skype installed are vulnerable to having their lock screen bypassed and being "attack-dialed."

 9 Android Tools That Boost Security, Privacy
9 Android Tools That Boost Security, Privacy
(click image for larger view)
More than 100 million Android devices could have their lock screens bypassed via a bug in the latest version of Skype.

That warning was sounded Monday by "Pulser," the developer administrator for XDA-Developers Forum, who said he'd tested the attack on the latest version of Skype (3.2.0.6673), which was released Monday, and multiple Android devices, including a Huawei Premia 4G, Samsung Galaxy Note 2 and Sony Xperia Z.

"The Skype for Android application appears to have a bug which permits the Android inbuilt lock screen (i.e., pattern, PIN, password) to be bypassed relatively easily, if the device is logged into Skype, and the 'attacker' is able to call the 'victim' on Skype," he said in a post to the Full Disclosure mailing list. He reported verifying the attack using two different Skype accounts and two devices, one of which was the target, which had its lock screen active and engaged.

[ Google offers tips for online security. Read Google Shares Advice On Wi-Fi Security. ]

According to Google Play, the Skype app has been installed on between 100 million and 500 million Android devices.

The attack works by sending a Skype call to the target device, Pulser explained, which will cause it to wake, ring, and display a prompt on the screen to answer or reject the call. After the call is accepted via the green answer button, the attacker must then end the call, which will cause the target device to again display the lock screen. But turning off that lock screen -- by tapping the power button once -- and then turning it back on again will then bypass the lock screen. "It will remain bypassed until the device is rebooted," Pulser explained, thus giving a would-be attacker full access to the device.

Reached by email, a press contact for Skype, which is owned by Microsoft, wasn't immediately able to comment on the bug report.

Pulser said the lock screen bypass resembles, ironically, a similar vulnerability -- discovered in April by Vietnamese information security firm Bkav -- which affected an Android app built by Skype rival Viber, which is likewise installed on over 100 million Android devices. Using the bug in Viber's Android app, which has since been patched, an attacker could send a Viber message to a target that also had the software installed, which would trigger a pop-up message. By ending the call from the attack phone, the attacker could then press the "back" button on the targeted device to bypass the lock screen and gain full access.

Smartphones and tablets running Android aren't the only devices that have suffered lock-screen-bypass vulnerabilities. Earlier this year, for example, reports surfaced of a lock screen bypass in iPhone 5, running iOS 6.1, that could be invoked by dialing and canceling an emergency call, then holding down the power button twice. Security experts reported that the vulnerability resembled a similar bug that was found in iOS 4.1 and patched in iOS 4.2.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVE-2012-5487
Published: 2014-09-30
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVE-2012-5488
Published: 2014-09-30
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVE-2012-5489
Published: 2014-09-30
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.