Security Architecture, Endpoint/Device Security, Endpoint/Device Security, Security Strategy, Plan, Budget, Vulnerability Management, Governance, Risk and Compliance, Compliance Management, Privacy, Endpoint/Device Security, Endpoint/Device Security, Endpoint/Device Security

Kernel vulnerability in Qualcomm processors weakens Android phone encryption

A security researcher looks to have discovered an Achilles heel in the way millions of Android phones perform encryption, leaving these mobile devices potentially vulnerable to advanced hacking techniques.

The problem specifically exists in Android phones running on certain Qualcomm Snapdragon processors. Consequently, Qualcomm and OEMs could comply with law enforcement to break Full Disk encryption if they wished to cooperate, researcher Gal Beniamini wrote in a blog post.

Essentially, a critical program designed to help protect devices' encryption keys runs in a segmented “TrustZone” within the Qualcomm processor itself, which is supposed to be more secure than the Android operating system. However, a kernel vulnerability within TrustZone is in essence leaking the encryption keys, allowing adversaries to use these keys off-device to break Full Disk Encryption via brute-force attack, without fear of triggering the mechanism that would normally erase files after a certain number of guesses.

Bradley Barth

As director of community content at CyberRisk Alliance, Bradley Barth develops content for SC Media online conferences and events, as well as video/multimedia projects. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.