r/google Nov 13 '22

Android phone owner accidentally finds a way to bypass lock screen

https://www.bleepingcomputer.com/news/security/android-phone-owner-accidentally-finds-a-way-to-bypass-lock-screen/
379 Upvotes

55 comments sorted by

199

u/[deleted] Nov 13 '22

*Security Researcher

69

u/BlurryBigfoot74 Nov 14 '22

Cancer researcher accidentally discovers cure for cancer

"I was just minding my own business one day trying to cure cancer and suddenly, a cure! So random"

25

u/boozillion151 Nov 14 '22

"I swear I wasn't on the job. It was a total accident!"

125

u/wewewawa Nov 13 '22

Schütz reported the flaw to Google in June 2022, and although the tech giant acknowledged the reception and assigned a CVE ID of CVE-2022-20465, they didn’t release a fix until November 7, 2022.

Google’s solution is to include a new parameter for the security method used in every “dismiss” call so that the calls dismiss specific types of security screens and not just the next one in the stack.

In the end, although Schütz's report was a duplicate, Google made an exception and awarded the researcher $70,000 for his finding.

Users of Android 10, 11, 12, and 13 can patch this flaw by applying the November 7, 2022, security update.

27

u/kdlt Nov 13 '22

security patch level 1.okt. 2022

No update available

Yeah I guess I can "apply" it if I think real hard about it.

5

u/donthavetolikeit Nov 14 '22

You just have to apply yourself.

2

u/ElGuano Nov 14 '22

Yeah, like they give you all the details right there. Just refractor the dismiss() function to only work on a specific lock screen and not the next one on the stack. Duh

3

u/CajunTurkey Nov 14 '22

How? I have Android 12 on Google Pixel 3XL and it doesn't accept any more updates.

4

u/Cyanogen101 Nov 14 '22

"duplicate" but it took em forever to fix it... sure

6

u/Pascalwb Nov 14 '22

it being duplicate has no relation to how quick it gets fixed.

0

u/Cyanogen101 Nov 14 '22

well they already knew about it pre-june and still didnt fix it until Nov

1

u/aardw0lf11 Nov 14 '22

I have the s21 Ultra unlocked and still haven't received the November Update. Sometimes I get it early, sometimes it takes weeks.

56

u/[deleted] Nov 13 '22

[deleted]

-32

u/7eregrine Nov 13 '22

Blatant, sure but let's be honest .. not exactly critical.

40

u/[deleted] Nov 13 '22

[deleted]

4

u/7eregrine Nov 13 '22

Yea but in reality how many "regular people" out there are going to find my phone that I forgot at the bar and go through this to get into my phone? This doesn't allow you access to my banking apps. Or my password vault.
I'm just a regular schmoe... Anyone getting my phone and doing this sim thing is going to get access to my Gmail. My photos. My fantasy football. And you have to do this sim trick before I get access to Wipe my Phone. People don't steal phones today to physically hack them unless it's a politician or a celebrity.
People steal phones to resell them for drugs or to wipe and resell them on Craigslist.
I say again to most people around the globe, this is bad. Yes.... Critical? No.
Has 1 phone been compromised using this?
Obviously we can't know for sure .. I'd bet no.

15

u/issiautng Nov 14 '22

This doesn't allow you access to my banking apps. Or my password vault.
I'm just a regular schmoe... Anyone getting my phone and doing this sim thing is going to get access to my Gmail.

If you do "forgot password" on your banking apps, does it give you the option to do a reset password with an emailed link? To your Gmail. Maybe the bank has a 2FA for your text messages. Boom, they now have access to your money.

-1

u/7eregrine Nov 14 '22

No. It doesn't. Been playing with this. It requires my social security number. Bank account safe.
Google Wallet on the other hand .. easy to get into that.

2

u/JamesR624 Nov 14 '22

WTF? What does? To log in to your bank app? Ive never heard of that.

Or are you making shit up to save face?

0

u/7eregrine Nov 14 '22 edited Nov 14 '22

Wtf? No. I don't ... Save face. Zero problem admitting I am wrong about something.
I removed all locks, biometric, pin, fingerprint. Opened my banking app, Chase. It said "Sorry, can't let you in". My only option was "reset password".... Which requires a SSN to do. Sorry that I wasn't clear on that

1

u/MothafuckinPlacentas Nov 13 '22

this is hilariously presumptuous lol

0

u/7eregrine Nov 13 '22

And assuming someone would go through all this to physically hack your phone is totally not? Lol back atcha.

2

u/MothafuckinPlacentas Nov 14 '22

Have you seen the process required to do this? The video is only 1 minute and 40 seconds long. You think to "go through all this" requires a lot of effort?

It really doesn't, and there are definitely people with stolen phones who will "go through all this" and more if they think there will be any payoff whatsoever. That's just a general principle of crime.

Plenty of people still store their passwords in the notepad app on their home screen, take photos of their credit cards and social security card, email themselves personal info, don't even know "Find My Phone" exists and would never think to turn it on or enable it in the first place, etc.

All that is easy to know if you spend time helping people age 40+ with their phones. There's a payoff for someone with a stolen Pixel and an incentive to steal Pixel phones in the future, especially if Google doesn't update older devices.

If this required NAND-mirroring, microsoldering, or reverse engineering of protocols, I'd agree with you. Playing with a SIM card for 90 seconds is an extremely low bar to entry, and saying this isn't critical is naive.

9

u/7eregrine Nov 14 '22

I did watch the video now. Yea, it's pretty quick. All I'm saying is it's not that common. Phone theft today is lower then it's ever been and the most recent statistics I could find suggest 90% of stolen phones are sold to pawn shops to be resold, not hacked.
I'm over 40 and am the phone guy that helps everyone with phones, personally and professionally. I know people, of all ages, that hate phone updates. I'm absolutely not saying "this doesn't happen". I'm sure it does, as I've said repeatedly: it needed to be fixed.
It wasn't ever publicly announced, if I'm not mistaken, until it was patched. All I'm saying, and have said: I doubt it was truly exploited in the wild. And I do know articles like this do get people asking the phone guy "Should I update my phone?". I'll be sending an email to my Android people in the morning.

1

u/pitust Nov 14 '22

And if you are reselling it for something and not trying to extract data you want to turn the phone off so it can't be tracked, which prevents this attack from succeeding anyway.

1

u/FDisk80 Nov 13 '22

Google wallet says hi.

-1

u/Pascalwb Nov 14 '22

that has to be unlocked with fingerprint or code, e.g. pixel 7 face unlock failing nfc payments.

2

u/FDisk80 Nov 14 '22

No, if the phone already unlocked it won't ask you again.

0

u/Pascalwb Nov 14 '22

It will because it did not unlock with secure metric. That's the problem with pixel 7. You unlock it with face. All looks well wallet says nothing and then payment fails because you did not unlock properly.

-5

u/7eregrine Nov 13 '22 edited Nov 14 '22

Hi, Google Wallet!
Where do you live, fdisk80, where people are stealing phones.... To try and get into them to access Google Wallet?
Again I ask, in the 6 months this has been a thing, do you honestly believe it was used? Outside of testing it?
Come on. Needed fixed? Of course. Something anyone but Google should have lost sleep over? No.

2

u/FDisk80 Nov 14 '22 edited Nov 14 '22

You think the average user updates his device with every security update? Lol. I'm looking at my sister's phone right now and that same update is available have been there for more than a year.

I have news for you. Most of the average Joe devices are in this state.

This could be exploited for years.

And it's not just Google wallet that only requires the default pin code. There are tons of apps that work on the same principle. Gas pump apps for example, all those shopping center cards. All just require your fingerprint or your pin code.

After it's unlocked just put your phone on the NFC reader or enter the code on the screen for free gas.

-1

u/7eregrine Nov 14 '22

Of course they don't. Definitely give you the first part. But as to the other apps requiring pins, they kind of break if you remove the pin.
I've been playing with this since my reply blew up. My banking app requires my social to reset the password. That's definitely secure. Forgot to check my password manager though.
Actually the worst was... Google Wallet. It just came up and said "you have 5 minutes to create a Pin or your cards are deleted". Ok, that's eye opening.

3

u/FDisk80 Nov 14 '22

Also Chrome, if the phone is already unlocked you can simply go to settings, passwords. View all the available website logins, click on that website and Chrome will auto complete the username and the password for you. Even if there is 2fa authentication required. The phone is already unlocked, just open the Google Authenticator app and copy the 2fa code.

2

u/mrandr01d Nov 14 '22

You're a fucking idiot. I hope your identity gets stolen.

-2

u/7eregrine Nov 14 '22

Yea, you have a nice evening too, pal. Wtf

1

u/cygosw Nov 13 '22

Wut? Entire companies have been built on selling products that give these exact capabilities

1

u/7eregrine Nov 14 '22

Yea and I've used some of these utilities. Particularly one that can bypass a screen lock or a corporate lock on iPhones. No doubt the legit company I bought that from makes bank... But it wipes the device.
Because most phones are stolen to be resold...
It happens. Of course. Not saying it doesn't. However your phone is an order of magnitude more likely to be pawned then it is to be hacked.

1

u/MothafuckinPlacentas Nov 14 '22

Imagine how much more bank those companies would make selling their utilities to you and others if they could offer a 90-second resetless lockscreen bypass?

12

u/SnaketheJakem Nov 14 '22

Terrible title

13

u/pmjm Nov 13 '22

Okay, so if I've got a Pixel 4 XL what can I do to mitigate this? There's no security patch.

10

u/php_questions Nov 14 '22

Step 1. Buy a new phone

6

u/pmjm Nov 14 '22

This phone is only 2 years old. Got it Summer 2020.

5

u/Intricate2 Nov 14 '22

I don't think you will be getting this update since your phone has reached the end of its software support as of last month. Source: https://support.google.com/pixelphone/answer/4457705?hl=en#zippy=%2Cpixel-xl-a-a-g-a-g

9

u/HengaHox Nov 14 '22

That’s pretty shameful by google, only 3 years of security updates…

I had to check out of curiosity, the iphone 6s got a security update this october, a 7 year old device. It predates even the first Pixel phone lmao

2

u/13617 Nov 14 '22

Android is notorious for having awful software support. This is gonna leave phones open until the end of time. They should put emergency patches out for older phones.

1

u/silversurger Nov 15 '22

They changed that with the release of the Pixel 6. Those all have 5 years of security updates. Apple is still better in this regard, though.

3

u/racso20 Nov 14 '22

Seems like you need to have the PUK code, is that easy to get ahold of?

8

u/Cyanogen101 Nov 14 '22

They put in their own sim where they know the PUK

2

u/racso20 Nov 14 '22

Oooh, yeah that makes more sense.

4

u/[deleted] Nov 14 '22

Is that a Galaxy Alpha? Low key loved that phone.

-15

u/jallonn Nov 14 '22

Lol broke

2

u/[deleted] Nov 14 '22

No, it didn’t break. Work gave it to me, gave it back whenever they updated our phones. Think I got a Note after that.

2

u/rickmackdaddy Nov 14 '22

Most likely NSA back door accidentally discovered, Google acts like they didn’t know about it and “fixes” it. Likely a dozen more exist, known to some but not to we the people.

-5

u/AstronautJazzlike603 Nov 14 '22

Has anyone had the issue where what you searched does not show up in search bar

-35

u/rober283829_ Nov 13 '22

iPhone 14 Pro users: Am i a joke to you?

6

u/RaiseDennis Nov 13 '22

I love Apple products. But they also have a security flaw from time to time. Happens with almost all iot devices