PSA: Android Apps Can Collect Camera, Microphone, and GPS Data without Permission While Device Is Locked

Erez Yalon, reporting for Checkmarx:

After a detailed analysis of the Google Camera app, our team found that by manipulating specific actions and intents, an attacker can control the app to take photos and/or record videos through a rogue application that has no permissions to do so. Additionally, we found that certain attack scenarios enable malicious actors to circumvent various storage permission policies, giving them access to stored videos and photos, as well as GPS metadata embedded in photos, to locate the user by taking a photo or video and parsing the proper EXIF data. This same technique also applied to Samsung’s Camera app.

In doing so, our researchers determined a way to enable a rogue application to force the camera apps to take photos and record video, even if the phone is locked or the screen is turned off. Our researchers could do the same even when a user was is in the middle of a voice call.

Android devices have always been user hostile, but this example is startling. If you have an Android device, it is truly time to switch.

I’ll admit, I’ve always had iPhones, so it’s easy for me to say that Android users should switch teams. I have friends who’ve always had Androids, and we occasionally rib each other over our loyalty to one brand or the other, but this is a lot bigger than that; I’m no longer suggesting that they switch out of jest, now I’m making those recommendations because I care about them and I don’t want to see them taken advantage of by devices they think they can trust.

I don’t care what team you picked, I don’t care what team I picked, the truth is that, at a technical level, one of these systems was built from the ground up in a way that prevents bad actors from gaining unfettered access to your device’s camera, microphone, and GPS, and the other was not.