Android Scam Call And SMS Security Is Undone By HTML Exploiting Malware

Android’s built-in protection, which flags warnings about apps trying to send premium rate messages without user consent, can be manipulated by malware to display a message controlled by malicious code.

Researchers from MWR Labs discovered a flaw in the Android Telephony API, which handles SMS and MMS sending and receiving on an Android smartphone, and noted that it could lead to users being tricked into sending premium rate messages despite thinking they are being protected by Android’s security features.

The security feature normally blocks premium messages with a prompt warning users of the cost and the app’s intentions, then asking them if the wish to continue to send the premium message.

HTML hacking

The malware can bypass the Android Telephony API by using HTML tags in the malicious application which governs how the the API displays a warning message.

“MWR Labs found that this protection could be manipulated by the malware running on the device. The warning message is partly based on the application’s name. By including special characters, it is possible to change the message from the standard message, into something that the user is more likely to press the “send” button for,” said Rob Miller, head of operational technology at MWR InfoSecurity.

“By pressing the send button the phone would then send a premium rate SMS message without further interaction with the user.”

Miller noted that Google issued a fix for the flaw in its latest Android Security Bulletin, but it is up to hardware OEMs, like HTC and Samsung to rollout the fix to their own devices, meaning the flaw may still be ripe for exploitation by malicious code.

Google’s Android has come under quite a bit of fire from software vulnerabilities and malware over the past few week, with it being forced to pull four spyware-riddled apps from the Play Store, as well as patch 55 vulnerabilities is its Android September update.

Quiz: What do you know about cybersecurity in 2016?

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

Recent Posts

TikTok Viewed As Chinese Influence Tool By Most Americans – Poll

Most people in the United States view TikTok as a Chinese influence tool a poll…

11 hours ago

Ofcom Confirms OnlyFans Investigation Over Age Verification

UK regulator confirms it is investigating whether OnlyFans is doing enough to prevent children accessing…

11 hours ago

Ex Google Staff Fired Over Israel Protest File NLRB Complaint

Dismissed staff file complaint with a US labor board, and allege Google unlawfully terminated their…

12 hours ago

Tesla Axes Entire Supercharger Team, Plus Senior Executives

Elon Musk dismisses two senior Tesla executives, plus the entire division that runs Tesla's Supercharger…

14 hours ago

Microsoft, OpenAI Sued By More Newspaper Publishers

Eight newspaper publishers in the US allege Microsoft and OpenAI used their millions of their…

15 hours ago

Binance’s Changpeng Zhao Sentenced To Four Months In Prison

US judge sentences Binance founder, Changpeng Zhao, to four months in prison for ignoring money…

18 hours ago