Monday, 21 November 2022 06:03

Hackers found a way to unlock your Android phone without your password. This is what to do

Rate this item
(0 votes)

Your phone’s lock screen is supposed to be a safeguard against the world (and accidental unlocks in your pocket). When it’s locked, your phone can’t be opened without either the passcode, a face scan, or a fingerprint. If you lose your phone or someone snatches it from you, you can rest assured they won’t be able to do anything with it. Except right now they can, thanks to a recently discovered vulnerability allowing anyone to bypass an Android device’s lock screen.

As reported by Bleeping Computer, cybersecurity researcher David Schütz discovered a way to unlock both a Google Pixel 6 and Pixel 5 without needing to know the passcode. It happened after his Pixel 6 ran out of charge, and after he incorrectly entered his PIN wrong three times. His SIM card was then locked, so he entered the PUK (Personal Unblocking Key) to restore it.

However, once the SIM was recovered, the Pixel asked him to scan his fingerprint. That shouldn’t happen, since Pixels (as well as most phones) require you to enter the passcode in order to unlock after a reboot. You shouldn’t have the option to use your fingerprint to unlock the phone until after one successful unlock with the passcode.

From there, Schütz realized there was a legitimate security flaw here. If an attacker inserts their own SIM into a target’s Android, then enters the wrong SIM PIN three times, they can enter their SIM’s PUK to be able to create a new SIM PIN. Once they do, they bypass the lock screen entirely and access the phone.

Schütz brought this flaw to Google’s attention back in June of this year, but it took the company five months to finally push a patch. Still, it’s good there is a patch: It’s not clear how long this vulnerability was actually floating around, potentially putting millions of Androids in jeopardy.

How to fix the latest lock screen security flaw on Android

If you have a phone running Android 10, 11, 12, or 13, you need to install the November 2022 security update in order to patch this vulnerability. If you already installed the patch, you’re good to go! But otherwise, install it ASAP.

To install a security patch on Android, head to Settings > System > System Update, then allow the OS to look for a new update. If there’s one available, you can download and install it. You can also check for security updates from Settings > Security > Google Security checkup.

 

Lifehacker

December 25, 2024

Investors add N500bn profit on Christmas Eve to the N1trn raked in last week as…

The Nigerian Exchange (NGX) is ending the year on a high note, with investors adding…
December 20, 2024

Atiku questions alleged hack of NBS website, says timing suspicious

Former Vice President Atiku Abubakar has raised concerns over the recent claim that the website…
December 25, 2024

Why Christmas and the birth of Jesus are all about hope, peace, joy and love

The Advent season is about preparing our hearts, minds and souls to welcome the birth…
December 21, 2024

‘Professional Back-Scratchers’ charge up to $130 per hour

The Scratcher Girls is an unconventional relaxation therapy studio that charges clients up to $130…
December 21, 2024

NAFDAC busts illegal rice repackaging operations in Nasarawa, Abuja

The National Agency for Food and Drug Administration and Control (NAFDAC) has cracked down on…
December 26, 2024

What to know after Day 1036 of Russia-Ukraine war

WESTERN PERSPECTIVE Russia launches 'inhuman' Christmas Day attacks, Ukraine says Russia attacked Ukraine's energy system…
December 25, 2024

Stem cell therapy to correct heart failure in children could 'transform lives'

Renowned visionary English physician William Harvey wrote in 1651 about how our blood contains all…
December 17, 2024

Ademola Lookman named 2024 CAF Men’s Player of the year. These players won in other…

Ademola Lookman, the Super Eagles winger, was crowned the 2024 CAF Men’s Player of the…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2024 NewsScroll. All rights reserved.