• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Elon Musk on MacKenzie Scott giving away $26 billion of her fortune: 'Sadly,' it makes the world a worse place

2

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

3

Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster

1

Elon Musk on MacKenzie Scott giving away $26 billion of her fortune: 'Sadly,' it makes the world a worse place

2

MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year

3

Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster
Techstagefright

Stagefright is back: More than 1 billion phones can be hacked with 1 video or song

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
October 1, 2015, 11:56 AM ET
Google's Android mobile OS.
Google's Android mobile OS.Photograph by Bloomberg via Getty Images
Add Fortune on Google for similar content.

It’s time to evacuate the Android dance floor—lest you be infected by the sound.

Two new critical vulnerabilities in Google’s mobile operating system announced by security researchers on Thursday put more than a billion Android devices at risk of being hacked. That means “almost every Android device” is affected, ranging from Android version 1.0 to the latest version 5.0, also known as “lollipop,” the researcher said.

Attackers can exploit these computer bugs by tricking users into visiting websites that host malicious MP3 or MP4 files. Once a victim previews one of these infected multimedia files, which commonly package music or video, that person’s machine can swiftly be compromised. The issue involves how Android processes these files’ metadata through a media playback engine named Stagefright.

This is not the first time that researchers have found this portion of Android’s code to be massively vulnerable. Zimperium zLabs, the mobile security firm that discovered the flaws, disclosed a set of seven monumental Stragefright bugs earlier this year. Those vulnerabilities could have enabled hackers to hijack as many as 950 million Android devices through a single infected multimedia text message.

Like the first set of Stagefright bugs, the latest couple—dubbed “Stagefright 2.0” by the researchers—allows attackers to take control of a compromised device and to access its data, photos, camera, and microphone. Taken together, the new issues are even more pervasive as they affect more devices.

The first of the new bugs—labeled CVE-2015-6602—affects nearly every Android device released since the first generation of the software debuted in 2008. The second bug—CVE-2015-3876—impacts versions 5.0 and up, and makes the problems easier to trigger.

Fortune spoke to Zuk Avraham, founder and chairman of Zimperium, about the firm’s findings. Although he withheld certain information (to prevent others from taking advantage of the bugs), he did compare them to the first generation Stagefright flaws. “It’s as critical a vulnerability,” he said. “It can do the same kind of damage.”

Since Google (GOOG) has, as a result of the first Stagefright disclosures, patched the mechanism in its Hangouts and Messenger apps by which Android automatically processed media files upon receipt, that means exploiting Stagefright 2.0 requires a different tactic. Simply sending an infected MP3 or MP4 filed to a victim will not immediately detonate its payload. Instead, the attacker must trick a recipient into either viewing a video or listening to a song via a compromised network, through a web browser, or through a vulnerable instant messenger, media player, or other third-party app.

Avraham added that his team had not invested the time to determine which apps and media players in particular might be vulnerable, since many of these are vendor or carrier-specific and would have taken too long given the variety of applications within the fragmented Android manufacturing ecosystem. Android devices of the version 5.0 and above, however, don’t need the additionally vulnerable apps, he said. These devices instead can be “hacked out of the box.”

Joshua Drake, who headed research on this project as well as the prior work, disclosed the bugs to Google on August 15. “These issues are equally exploitable as the original Stagefright issues,” Drake told Fortune via email, passed along by a spokesperson. They “have been assigned a critical rating by the Android Security Team under the following clause,” he continued, pointing to an Android security resources page that contains severity ratings.

Under “critical” one finds the following: “Remote privileged code execution (execution at a privilege level that third-party apps cannot obtain.” That’s the bucket Stagefright 2.0 falls under.

A Google spokesperson told Fortune via email that the company already has patches in the queue. “As announced in August, Android is using a monthly security update process,” the spokesperson said, referencing the company’s decision to release fixes on a more regular schedule in the wake of the first Stagefright disclosures. “Issues including the ones Zimperium reported, will be patched in the October Monthly Security Update for Android rolling out Monday, October 5th and will be posted about here.”

That means patches will be publicly available for the company’s Nexus devices starting Oct. 5th. The spokesperson told Fortune that the company provided fixes to its Android manufacturing partners and carriers on Sept. 10, and that it is working with those companies “to deliver updates as soon as possible.” Attacks exploiting the bugs have not yet been reported in the wild, the spokesperson said.

Fortune is still waiting to learn when Android’s partnering phone manufacturers plan to roll out their patches. We will update this story when we hear back.

You can find out whether your device is vulnerable using Zimperium’s Stagefright detector app, which is available in the Google Play store. In the meantime, be extra cautious of the media you download. Stop these beats from killing you.

Do not—I repeat, do not—let the music take you underground.

For more on Stagefright, watch this video below.

 

Subscribe to Data Sheet, Fortune’s daily business-tech newsletter.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

wb
CommentaryLeadership
I grew BDO from $600 million to $3.4 billion. Here’s the 3-part formula that made it possible
By Wayne BersonJune 30, 2026
1 hour ago
vinod
CommentaryData centers
Vinod Khosla: AI’s energy crisis has a fix — and it doesn’t need the grid
By Vinod KhoslaJune 30, 2026
1 hour ago
Jamie Dimon isn’t giving up the top job. That’s turned JPMorgan into a poaching ground for CEO talent
C-SuiteNext to Lead
Jamie Dimon isn’t giving up the top job. That’s turned JPMorgan into a poaching ground for CEO talent
By Ruth UmohJune 30, 2026
1 hour ago
Comcast’s split brings former CFO Michael Angelakis back as CEO
AICFO Daily
Comcast’s split brings former CFO Michael Angelakis back as CEO
By Sheryl EstradaJune 30, 2026
2 hours ago
marc
Commentary250 Years of Innovation
The U.S. Army is opening military bases to private billions — here’s why that changes everything for the next 250 years
By Marc AndersenJune 30, 2026
2 hours ago
The VCs betting founders need a village, not a blank check
NewslettersTerm Sheet
The VCs betting founders need a village, not a blank check
By Allie GarfinkleJune 30, 2026
3 hours ago

Most Popular

Elon Musk on MacKenzie Scott giving away $26 billion of her fortune: 'Sadly,' it makes the world a worse place
Success
Elon Musk on MacKenzie Scott giving away $26 billion of her fortune: 'Sadly,' it makes the world a worse place
By Sydney LakeJune 29, 2026
22 hours ago
MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
Success
MacKenzie Scott alone accounted for one-third of America's $19.2 billion in megagifts last year
By Sydney LakeJune 25, 2026
5 days ago
Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster
Success
Philanthropy leader at Warren Buffett and Bill Gates’ Giving Pledge says children of billionaires are pushing them to give their wealth away faster
By Preston ForeJune 27, 2026
3 days ago
The retired college professor fighting a $313 trespassing ticket in Wisconsin thinks he's part of a national struggle
Environment
The retired college professor fighting a $313 trespassing ticket in Wisconsin thinks he's part of a national struggle
By Catherina GioinoJune 28, 2026
2 days ago
Current price of oil as of June 29, 2026
Personal Finance
Current price of oil as of June 29, 2026
By Joseph HostetlerJune 29, 2026
1 day ago
'Humanity has chosen to become idiots': This Brown professor switched to take-home exams after a mass shooting and discovered mass cheating
AI
'Humanity has chosen to become idiots': This Brown professor switched to take-home exams after a mass shooting and discovered mass cheating
By Catherina GioinoJune 29, 2026
16 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.