Android Baseband Flaws Allow Hackers to Intercept Calls and Block Service
Security researchers discover that popular Android phones inadvertently grant Bluetooth and USB accessories access to sensitive baseband software. This flaw exposes unique device identifiers and allows attackers to intercept calls or disrupt cellular service entirely.
Security researchers uncover a significant weakness in several popular Android phones that allows accessories to access the phone's underlying baseband software. This inadvertent access means that connected Bluetooth or USB devices, like headphones, serve as an entry point for attackers to interact directly with the modem. The vulnerability affects at least ten well-known devices, including Google's Pixel 2, Huawei's Nexus 6P, and Samsung's Galaxy S8+.
By exploiting a vulnerable accessory, an attacker runs manipulated AT commands on the connected phone to execute unauthorized actions. These commands force the device to reveal sensitive information, such as its unique IMEI and IMSI identifiers. Furthermore, the attackers use these commands to downgrade the target's cellular connection, forward incoming phone calls to another number, or block all calls and internet access completely.
The researchers from Purdue University and the University of Iowa develop a tool called ATFuzzer to identify these problematic commands during their testing. They discover 14 specific commands that manipulate vulnerable Android phones, leading to severe consequences ranging from data exposure to total service disruption. The team plans to present these concerning findings to the public next month to highlight the critical need for better isolation between mobile accessories and baseband firmware.