hack android with NFC Vulnerability

What is NFC?

NFC means Near Field Communication contains a set of protocols allow android to establish a connection or the shortest range connection.
NFC is used in day-to-day life for contactless payments at malls, movies Thearter, etc, file sharing and access controls.

NFC beaming of applications between devices using Android OS bypasses some security controls such as install unknown application,” this let a malicious phone or malicious payment terminal to install malware on the phone said by Nightwatch Cybersecurity team.

What is NFC Vulnerability?
NFC Vulnerability is affecting the android version of 8 and above and the vulnerability traced by Nightwatch as CVE-2019-2114 and it is said that the vulnerability is fixed in October in the android bulletin.

Starting from Android 8, users need to enable permission for individual apps to install unknown APK files. But if any system application will be “automatically whitelisted and would not prompt the user for this permission,” Night watched researchers said.

The NFC is one of the applications that have the permission to install other applications, if the NFC and Android Beam enabled devices taps any malicious phone or malicious NFC payment terminal, this let malware to be installed on the device bypassing “install unknown apps” prompt.

Following are the steps to replicate a malicious drive-by install:

  1. Setup two phones with NFC and Android beam enabled.
  2. Download any APK file on the “sender” phone (something like
  3. this APK from GitHub).
  4. Go to the file manager in the “sender” phone, tap the file and select “Share”. Then select “Android Beam” as the sharing method,
  5. Bring two phones together and complete the transfer.
  6. After this is done, go to the receiver phone, tap the “Beam completed” notification, and tap the file. It will skip directly to the install prompt, bypassing the “Install unknown apps” check.

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Some Dark web Links

Cyber Security Audits