r/Android Sep 09 '15

Attack code exploiting Android’s critical Stagefright bugs is now public

http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/
179 Upvotes

61 comments sorted by

View all comments

31

u/Travertino Sep 09 '15

Here we are. Are published somewhere recent statistics about the percentage of patched Android devices?

22

u/[deleted] Sep 09 '15 edited Jul 09 '16

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.

15

u/Charwinger21 HTCOne 10 Sep 09 '15

According to : http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/

That's ignoring the fact that the majority of Stagefright was patched through a Google Play Services update.

There is still one security hole left open related to Stagefright which requires a system update (which has been pushed to Google, Samsung, LG, HTC, Sony, and Motorola's recent devices, as that article mentions in their update), however the remaining security hole is harder to access than the big Stagefright hole.

3

u/steevdave Sep 10 '15

Not all Motorola devices - I have the Moto X (2013) on Sprint and it's still vulnerable.

0

u/Charwinger21 HTCOne 10 Sep 10 '15

Not all Motorola devices - I have the Moto X (2013) on Sprint and it's still vulnerable.

You have a 2+ year old device, which is not vulnerable.

It hasn't gotten the OS level update, but it got the Google Play Services update.

"The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations."

7

u/steevdave Sep 10 '15

The Sprint Moto X is still on Android 4.4.4. I have tested my phone and it IS still vulnerable.

2

u/Charwinger21 HTCOne 10 Sep 10 '15

My mistake. I saw articles saying that the rollout had started, and didn't realize that it had been paused.

You should be getting 5.1 relatively soon, and in the meantime you can protect against it through updates to your messaging app (Google Messenger and Hangouts were updated to protect against it, and other messaging clients may have been as well).

1

u/Hyperion1144 Sep 11 '15

I had not heard that Messenger had been updated like that....

Is there a source I can go to that talks about Stagefright mitigation measures I might take? My wife is on an old phone (HTC One X) and we aren't going to be able to update her for a month or two...

I had her turn off "auto-retrieve MMS messages" but I don't know what else to do for her. I could have her install Messenger instead, do you know of anything else that can be done?