How a malicious Android app could covertly turn the DSP in your MediaTek-powered phone into an eavesdropping bug
- Reference: 1637751609
- News link: https://www.theregister.co.uk/2021/11/24/mediatek_audio_vulnerabilty/
- Source link:
The infosec outfit believes as many as 37 per cent of smartphones globally are vulnerable. The flaws, patches for which were released last month, lie deep within handsets: in the code that controls an audio-processing unit inside system-on-chips designed by Taiwan's MediaTek.
Though its chips tend to power low-to-mid-end Android handhelds, MediaTek [1]leads the world in terms of smartphone chip shipments; its tech is used nearly everywhere. Its system-on-chips include a digital signal processor (DSP) for handling audio, and this is a customized Tensilica Xtensa processor that has its own special opcodes and registers.
[2]
Check Point Research says it was able to obtain and reverse-engineer MediaTek's firmware driving this DSP, and found it was an adapted FreeRTOS environment with code for processing audio and exchanging messages with the Android software stack running on the phone. This real-time OS starts multiple individual tasks for handling phone calls, capturing raw audio from the microphone, and so on.
[3]
[4]
This firmware was pulled from a Xiaomi Redmi Note 9 5G smartphone running Android 11 on a Dimensity 800U SoC, which was also used for testing that the security holes could be exploited.
Essentially, according to Check Point Research, it's possible for an unprivileged, malicious Android app to chain together vulnerabilities and oversights in MediaTek and phone makers' system libraries and driver code to escalate its privileges and send messages direct to the audio DSP firmware. This low-level firmware code has little in the way of secure coding, allowing its memory to be overwritten and execution hijacked on receiving these messages.
[5]
At this point, the malicious app can now potentially program the DSP to act like a covert listening bug, drawing from raw microphone audio flows, and run hidden programs. The technical details for these flaws should [6]appear here by the time you read this.
“MediaTek is known to be the most popular chip for mobile devices," said Slava Makkaveev, a security researcher at Check Point.
"Given its ubiquity in the world, we began to suspect that it could be used as an attack vector by potential hackers.
[7]
"Left unpatched, a hacker potentially could have exploited the vulnerabilities to listen in on conversations of Android users. Furthermore, the security flaws could have been misused by the device manufacturers themselves to create a massive eavesdropping campaign."
Mediatek's latest [8]Dimensity-series chips are among the components affected, we're told. Check Point Research said it can't right now share full details on how to achieve real-world exploitation "for ethical reasons."
[9]Mediatek unveils its first ARMv9 smartphone chip for advanced handsets
[10]Smartphone chip house Ziguang Zhanrui records 14,726.1% growth in China
[11]MediaTek's flagship 5G chip for top-of-the-line Android smartphones is coming right up
[12]MediaTek wants Windows 11 Arm PCs powered by its chips, not just Qualcomm's
MediaTek doesn't think anyone's abused these bugs in the wild, and has issued some fixes for its code to phone makers to then push to people's devices.
"Regarding the audio DSP vulnerability disclosed by Check Point, we worked diligently to validate the issue and make appropriate mitigations available to all OEMs," said Tiger Hsu, product security officer at MediaTek. "We have no evidence it is currently being exploited."
It's at least an interesting piece of research, though one wonders whether it might not be easier for an evil app to use a privilege-escalation flaw in the Android side of the device to eavesdrop on the user without having to delve into the custom DSP processor.
While patches are now out, you may want to check if your MediaTek-powered phone has actually been offered and installed the updates. The bugs CVE-2021-0661, CVE-2021-0662, and CVE-2021-0663 in the firmware were shared in October, and CVE-2021-0673 in MediaTek's hardware abstraction library is due to be released in December. The delay in patching the 0673 bug may be why full exploitation details are being withheld. We've asked Check Point Research for further info. ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2021/11/15/smartphone_chipmaker_rise/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZ5vv5@tN7wc6reMPcQXWwAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZ5vv5@tN7wc6reMPcQXWwAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZ5vv5@tN7wc6reMPcQXWwAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZ5vv5@tN7wc6reMPcQXWwAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://research.checkpoint.com/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZ5vv5@tN7wc6reMPcQXWwAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/11/17/mediatek_dimensity_smartphones/
[9] https://www.theregister.com/2021/11/19/mediatek_armv9_smartphone/
[10] https://www.theregister.com/2021/11/15/smartphone_chipmaker_rise/
[11] https://www.theregister.com/2021/11/17/mediatek_dimensity_smartphones/
[12] https://www.theregister.com/2021/10/27/mediatek_windows11_arm/
[13] https://whitepapers.theregister.com/
Re: Why even bother?
Depending on the app, triggering a microphone permission prompt may not be desired. Now, if one can use privilege escalation to get microphone permission without triggering the prompt, that's another thing.
Eavesdropping bug
I wouldn't worry about that. Given Google's attitude, as attested by their response to the undocumented mircophone array built into Nest units, I consider all Android powered smartphones eavesdropping bugs, in order not to be surprised at some later date.
Re: Eavesdropping bug
" I consider all Android powered smartphones eavesdropping bugs "
There, FTFY.
Re: Eavesdropping bug
"I consider all smartphones electronic devices--including those beyond my control--eavesdropping bugs"
There, FTFTFY.
Tensilica Xtensa, FreeRTOS, ...
So it's like a customised ESP32?
New fresh security holes
Great, another call to buy a new phone. Give me a break people, I hadn't time to unpack the last one yet!
Yeah, patches, sure will happen. Want a bridge with that? Premium location!
"Furthermore, the security flaws could have been misused by the device manufacturers themselves to create a massive eavesdropping campaign."
So, err, the Batman movie wasn't wrong? Use them all as echo-locators to build an image of the surroundings.
Why even bother?
Why couldn't that app just use the microphone?