To cut off all nearby phones with these Chinese chips, this is the bug to exploit
- Reference: 1654279616
- News link: https://www.theregister.co.uk/2022/06/03/uisoc-chip-flaw-check-point/
- Source link:
The vulnerability in the baseband – or radio modem – of UNISOC's chipset was found by folks at Check Point Research who were looking for ways the silicon could be used to remotely attack devices. It turns out the flaw doesn't just apply to lower-end smartphones but some smart TVs, too.
Check Point found attackers could transmit a specially designed radio packet to a nearby device to crash the firmware, ending that equipment's cellular connectivity, at least, presumably until it's rebooted. This would be achieved by broadcasting non-access stratum (NAS) messages over the air that when picked up and processed by UNISOC's firmware would end in a heap memory overwrite.
[1]
"We scanned NAS message handlers within a short period of time and found a vulnerability which can be used to disrupt the device's radio communication through a malformed packet," the researchers wrote in a detailed and fascinating [2]advisory this week.
[3]
[4]
"A hacker or a military unit can leverage such a vulnerability to neutralize communications in a specific location." They stressed that the flaw was in the firmware of the UNISOC chipset and not the Android operating system.
UNISOC is a 21-year-old chip designer based in China that spent the first 17 years of life known as Spreadtrum Communications, and that by 2011 was supplying chips for more than half of the mobile phones in the country. In 2018, the company changed its name to UNISOC. The chips are found mostly in smartphones in Asia and Africa due to the low prices of its silicon.
[5]
According to market analyst firm Counterpoint, UNISOC is the [6]fourth-largest smartphone chip house in the world, behind MediaTek, Qualcomm and Apple.
[7]Predator spyware sold with Chrome, Android zero-day exploits to monitor targets
[8]Upgrading to Android 12.1 ... in Windows 11: Telemetry disabled by default
[9]Safari is crippling the mobile market, and we never even noticed
[10]Ad-tech firms grab email addresses from forms before they're even submitted
This isn't the first time UNSOC's tech has come under scrutiny. In March, Kryptowire, a mobile security and privacy monitoring company, announced it had [11]found a vulnerability that, if exploited, would let bad actors take control of a device's functionality and the user data within it.
"The vulnerability allows intruders to access call and system logs, text messages, contacts, and other private data, video record the device's screen or use the external-facing camera to record video, or even take control of the device remotely, altering or wiping data," Kryptowire researchers said, adding that in December 2021 they disclosed the vulnerability to UNISCO and affected device manufacturers and carriers.
In this latest discovery, Check Point researchers reverse-engineered UNISOC's LTE protocol stack implementation. LTE networks comprise multiple components and protocols that form the evolved packet system (EPS) architecture.
In its tests, Check Point used a Motorola Moto G20 device with the Android January update. The smartphone is based on UNISOC's T700 chip.
[12]
The Check Point analysts focused on the information exchanged between the cellular network's equipment and people's devices as part of their everyday operation to stay connected and communicate. This exchanged data is contained in NAS messages. It turns out a specific type of packet – an EPS mobility management (EMM) packet – in a NAS message can trigger programming errors in the firmware's NAS handlers.
"The NAS protocol operates with high-level structures," the researchers wrote. "Therefore, it does not take much effort for an attacker to create a malformed EMM packet and send it to a target device. When a new NAS message arrives, the UNISOC modem parses it and creates internal objects based on the received data."
An attacker could thus, with a suitable broadcast resulting in a bad NAS message, remotely crash the modem, which could result in a denial-of-service – or possibly remote code execution, enabling the miscreant to get some control over the devices.
Check Point disclosed the flaw in May – which is tracked as CVE-2022-20210 – to UNISOC, and the chip biz produced a patch later that month. According to the cybersecurity company, Google will roll out this fix in its upcoming Android Security bulletin. Check Point recommended users update their operating system on their UNISOC-powered devices to the latest version, if possible.
"The smartphone modem is a prime target for hackers as it can be easily reached remotely through SMS or radio packet," the researchers wrote.
The result can be seen in the booming mobile security market, which analyst firm Allied Market Research said will grow from $3.3 billion in 2020 to [13]$22.1 billion in 2030 , driving in large part to the increase in online mobile payments, the use of mobile devices for tasks that involve sensitive information – such as banking information and credit card and social security numbers – and the ongoing adoption of bring-your-own-device (BYOD) policies in the workplace. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YpqEgljWsppnS15-jaadKgAAAFA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpqEgljWsppnS15-jaadKgAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpqEgljWsppnS15-jaadKgAAAFA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpqEgljWsppnS15-jaadKgAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.counterpointresearch.com/global-smartphone-ap-market-share/
[7] https://www.theregister.com/2022/05/24/predator_spyware_zero_days/
[8] https://www.theregister.com/2022/05/23/windows_subsystem_for_android/
[9] https://www.theregister.com/2022/05/23/opinion_column/
[10] https://www.theregister.com/2022/05/16/ad_companies_data/
[11] https://www.kryptowire.com/news/kryptowire-identifies-vulnerability-in-unisoc-chipset/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpqEgljWsppnS15-jaadKgAAAFA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.alliedmarketresearch.com/mobile-security-market
[14] https://whitepapers.theregister.com/
Re: The Terminator
Back in those days when you found a problem in a device then you worked to fix it, in this example you would probably just replace the chip with a new version, but these days you work to make them buy a new device.
I was working for a company in Oxford back in the 70's that found a problem with their tape decks, so I reworked the 8048 coding to fix it - I just fixed an 8-bit integer overflow (LOL).
Google will roll out this fix in its upcoming Android Security bulletin
Uh huh. And since these are apparently the cheapest of the cheap, I assume support ended the moment the customer walked out of the store and there's zero percent chance they'll get any updates.
This is nice and all
But don't believe for a second similar flaws don't exist in Qualcomm, Mediatek or Exynos modems.
Whether you have an iPhone, Samsung, or even a Google-free Android that you flashed a fully open source bootloader on and use pure 100% open source Android, its modem is running proprietary baseband software which is rarely if ever audited and almost certainly has multiple 0 days known by intelligence agencies (if you're lucky) as well as criminal organizations (if you're not) which can take over the entire device.
Re: This is nice and all
known by intelligence agencies (if you're lucky) as well as criminal organizations (if you're not)
Given how little they get paid, likely they supplement their income by selling to the underworld. I mean, we are at the times where the police is not capable of investigating a party they had their own people at...
Next level
UNISOC is a 21-year-old chip designer based in China that spent the first 17 years of life known as Spreadtrum Communications, and that by 2011 was supplying chips for more than half of the mobile phones in the country. In 2018, the company changed its name to UNISOC.
So he started when he was only 4? I know there is this stereotype that Asian children are much smarter, but this is like next level!
When I was 4 I was trying to drink water from a puddle and they were designing chips!
The Terminator
Robots pwning devices automagically screaming modem signals over the phone looked so much science fiction back in those days...