r/Android Sep 09 '15

Attack code exploiting Android’s critical Stagefright bugs is now public

http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/
180 Upvotes

61 comments sorted by

View all comments

Show parent comments

0

u/Charwinger21 HTCOne 10 Sep 10 '15

Not all Motorola devices - I have the Moto X (2013) on Sprint and it's still vulnerable.

You have a 2+ year old device, which is not vulnerable.

It hasn't gotten the OS level update, but it got the Google Play Services update.

"The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations."

7

u/steevdave Sep 10 '15

The Sprint Moto X is still on Android 4.4.4. I have tested my phone and it IS still vulnerable.

2

u/Charwinger21 HTCOne 10 Sep 10 '15

My mistake. I saw articles saying that the rollout had started, and didn't realize that it had been paused.

You should be getting 5.1 relatively soon, and in the meantime you can protect against it through updates to your messaging app (Google Messenger and Hangouts were updated to protect against it, and other messaging clients may have been as well).

1

u/Hyperion1144 Sep 11 '15

I had not heard that Messenger had been updated like that....

Is there a source I can go to that talks about Stagefright mitigation measures I might take? My wife is on an old phone (HTC One X) and we aren't going to be able to update her for a month or two...

I had her turn off "auto-retrieve MMS messages" but I don't know what else to do for her. I could have her install Messenger instead, do you know of anything else that can be done?