Industry News

Got an Android Phone? You owe this guy a beer.

The man referenced in the story stands on a rock in a hero's pose.

28-07-2015.  IT News reports that code already present on Android phones from version 2.2 onwards is vulnerable to memory corruption and can be exploited to fully compromise the device.

The security researcher who discovered the code, Joshua Drake from Zimperium, says that specially crafted exploits only need the phone number of the phone in order to execute.  A weaponised MMS is sent that can even be automatically deleted once the code is installed and executed.

It takes advantage of code already present on the phone, called Stagefright, to install and execute.

Google patched the issue within 48 hours of notification, but is reliant on your phone carrier to issue updates so for the time being, the vulnerability still exists worldwide on up to 950,000,000 phones.

Drake has so far not disclosed the working method he used to demonstrate the hack.  He will talk on the exploit at a Blackhat convention in August.

What reward did Google offer for the offer to save it from a huge problem?  $1,000.  He eventually talked them up to $1,337.  Equivalent to a touch over 2 Google shares.  At that price and considering the potential for damage and reward if used for the wrong purposes, I think they’re lucky he gave it to them…

Interestingly, he used to work for Rapid 7, the developer of Nexpose software, which we use to find vulnerabilities in networks.

James Walker

Other News

The Computer One logo with blue background
6 time winner of the
Channel Futures MSP 501 Winner logo white | Computer One
Local Government Procurement Approved Contractor logo | Computer One
Q-Mark ISO 9001 certified logo | Computer OneQ-Mark ISO 27001 certified logo | Computer One
© 2026 Computer One Australia.
arrow-right linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram