• Ping Us
  • Our Team
  • About Us
Friday, May 9, 2025
Digitalys Mag
  • Home
  • Cybersecurity
  • Technology
  • Events
    • All
    • Conferences
    • Pop Culture
    National Cyber Security Congress 2.0

    National Cyber Security Congress 2.0

    Ryujin’Con 0: Videos + Article

    Ryujin’Con 0: Videos + Article

    Banzai 2018: Video + Review

    Banzai 2018: Video + Review

    Comic Con Tunisia 2018

    Comic Con Tunisia 2018

    Calendrier culturel de l’été 2018 – updated

    Calendrier culturel de l’été 2018 – updated

    [Securiday 2018] End User Protection

    [Securiday 2018] End User Protection

    • Conferences
    • Pop Culture
  • Entertainment
    • All
    • Gaming
    • Manga/Anime/comics
    • Movies / Series
    Koei Tecmo Victim of  DataBreach

    Koei Tecmo Victim of DataBreach

    Détective Conan : les épisodes de l’histoire principale triées [part 1]

    Détective Conan : les épisodes de l’histoire principale triées [part 3]

    Epic Games Store down due to Free Grand Theft Auto V offer

    Epic Games Store down due to Free Grand Theft Auto V offer

    Steam Security Saga: 0-Days, patches and researchers debates

    Steam Security Saga: 0-Days, patches and researchers debates

    [Warning] Une faille critique dans tous les jeux Blizzard permettra aux Hackers de détourner des millions de PC

    [Warning] Une faille critique dans tous les jeux Blizzard permettra aux Hackers de détourner des millions de PC

    Le clavier MantisTek GK2 pour gamers contient un KEYLOGGER!!!

    Le clavier MantisTek GK2 pour gamers contient un KEYLOGGER!!!

    • Manga/Anime/comics
    • Movies / Series
    • Gaming
  • LifeStyle
  • Funny
  • Vlogs
No Result
View All Result
Digitalys Mag
  • Home
  • Cybersecurity
  • Technology
  • Events
    • All
    • Conferences
    • Pop Culture
    National Cyber Security Congress 2.0

    National Cyber Security Congress 2.0

    Ryujin’Con 0: Videos + Article

    Ryujin’Con 0: Videos + Article

    Banzai 2018: Video + Review

    Banzai 2018: Video + Review

    Comic Con Tunisia 2018

    Comic Con Tunisia 2018

    Calendrier culturel de l’été 2018 – updated

    Calendrier culturel de l’été 2018 – updated

    [Securiday 2018] End User Protection

    [Securiday 2018] End User Protection

    • Conferences
    • Pop Culture
  • Entertainment
    • All
    • Gaming
    • Manga/Anime/comics
    • Movies / Series
    Koei Tecmo Victim of  DataBreach

    Koei Tecmo Victim of DataBreach

    Détective Conan : les épisodes de l’histoire principale triées [part 1]

    Détective Conan : les épisodes de l’histoire principale triées [part 3]

    Epic Games Store down due to Free Grand Theft Auto V offer

    Epic Games Store down due to Free Grand Theft Auto V offer

    Steam Security Saga: 0-Days, patches and researchers debates

    Steam Security Saga: 0-Days, patches and researchers debates

    [Warning] Une faille critique dans tous les jeux Blizzard permettra aux Hackers de détourner des millions de PC

    [Warning] Une faille critique dans tous les jeux Blizzard permettra aux Hackers de détourner des millions de PC

    Le clavier MantisTek GK2 pour gamers contient un KEYLOGGER!!!

    Le clavier MantisTek GK2 pour gamers contient un KEYLOGGER!!!

    • Manga/Anime/comics
    • Movies / Series
    • Gaming
  • LifeStyle
  • Funny
  • Vlogs
No Result
View All Result
Digitalys Mag
No Result
View All Result

CVE-2019-2234 vulnerabilities in Android Camera Apps

Alyssa Berriche by Alyssa Berriche
29 November 2019
3 min read
CVE-2019-2234 vulnerabilities in Android Camera Apps
831
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

Cybersecurity experts from Checkmarx discovered multiple vulnerabilities in the Camera apps affecting millions, if not hundreds of millions, of Android devices that could allow other apps to record video, take pictures, and extract GPS data from media without having the required permissions.

Overview

The vulnerabilities are collectively tracked as CVE-2019-2234.

After analyzing the Google Pixel’s Camera app, Checkmarx researchers discovered numerous intents that could be combined to manipulate the device’s camera in order to take pictures and record video  through a rogue application that has no permissions to do so.

In other words, the apps that have the ‘Storage’ permission, which gives the app access to the device’s entire SD card and the media stored on it, also gives an app the ability to use the Camera app’s exposed intents without the permissions android.permission.CAMERA, android.permission.RECORD_AUDIO, android.permission.ACCESS_FINE_LOCATION, and android.permission.ACCESS_COARSE_LOCATION .

The researchers also determined a way to enable a rogue application to force the camera apps to take photos and record video, even if the phone is locked or the screen is turned off.

Severity: High

Affected systems

This vulnerability, known as CVE-2019-2234, is known to affect the Google Camera and Samsung Camera apps if they have not been updated since before July 2019.

Impact

Attackers could exploit them to conduct several activities, including recording videos, taking photos, recording voice calls, tracking the user’s location.

PoC of the attack

The experts developed a PoC weather application, without specific permissions, that established a persistent connection with the attacker’s command-and-control (C&C) server that was able to siphon any kind of data from the target phone, even when the rogue app was closed.

The operator of the C&C console can see which devices are connected to it, and perform the following actions (among others):

  • Take a photo on the victim’s phone and upload (retrieve) it to the C&C server
  • Record a video on the victim’s phone and upload (retrieve) it to the C&C server
  • Parse all of the latest photos for GPS tags and locate the phone on a global map
  • Operate in stealth mode whereby the phone is silenced while taking photos and recording videos
  • Wait for a voice call and automatically record:
    • Video from the victim’s side
    • Audio from both sides of the conversation

Patch and resolution

According to Google, this vulnerability in the Camera app was fixed in July 2019 via a Google Play Store update and a patch was issued to other vendors.

Samsung also confirmed to have addressed the issue.

Recommendations

All users are strongly advised to upgrade to the latest version of Android and make sure you are using the latest Camera app for your device.

References

  • https://www.checkmarx.com/blog/how-attackers-could-hijack-your-android-camera
  • https://www.bleepingcomputer.com/news/security/android-camera-app-bug-lets-apps-record-video-without-permission/
  • https://www.andreafortuna.org/2019/11/22/a-new-android-vulnerability-cve-2019-2234-allows-attackers-to-hijack-camera-app/
  • https://www.symantec.com/security-center/vulnerabilities/writeup/110913?om_rssid=sr-advisories
Tags: androidcamera appscvecybersecurityinfosecsamsungvulnerability
ShareTweetShareScan
Previous Post

Steam Security Saga: 0-Days, patches and researchers debates

Next Post

TikTok: multiple security issues

Alyssa Berriche

Alyssa Berriche

Cyber Threat Analyst & Security researcher. Founder and Technical Writer for DigitaLys-Mag

Related Posts

Cybersecurity

[Vulnerability] Zerologon – CVE-2020-1472 exploited in the wild

8 October 2020
National Cyber Security Congress 2.0
Conferences

National Cyber Security Congress 2.0

26 January 2020
Firefox users: Update your browser right now!
Cybersecurity

Firefox users: Update your browser right now!

10 January 2020
Next Post
TikTok: multiple security issues

TikTok: multiple security issues

Social Networks

  • 418 Fans
  • 141 Followers

Random Quote

Never apologize for having high standards. People who really want to be in your life will rise up to meet them.

Instagram

Follow-us on Instagram
Facebook Twitter Instagram Youtube
logo-digi

  • 40
  • 245
  • 2,474
  • 11,303
  • 110,403
  • 611,791
IMG 2504
20160430 085844
20170708 173551
IMG 2551
7
20180707 112615
IMG 2547
10
SAM 0019
20160424 103734
IMG 20180708 152408
20170415 102112

© 2019 Digitalys Mag - Personal Blog & Magazine.

No Result
View All Result
  • Home
  • Cybersecurity
  • Technology
  • Events
    • Conferences
    • Pop Culture
  • Entertainment
    • Manga/Anime/comics
    • Movies / Series
    • Gaming
  • LifeStyle
  • Funny
  • Vlogs

© 2019 Digitalys Mag - Personal Blog & Magazine.

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In