CVE-2020-0096 | Android ÌØÈ¨ÌáÉý·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-05-270x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-0096 |
ʱ ¼ä |
2020-05-27 |
|
Àà ÐÍ |
EOA |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Android <= 9.0 |
0x01 ·ì϶ÏêÇé
AndroidÊÇÃÀ¹ú¹È¸è£¨Google£©ºÍŰÕÐݳÖÉ豸ÁªÃË£¨¼ò³ÆOHA£©µÄÒ»Ì×ÒÔLinuxΪ»ù´¡µÄ¿ªÔ´²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£FrameworkÊÇÆäÖеÄÒ»¸öAndroid¿ò¼Ü×é¼þ¡£¡£¡£¡£¡£¡£¡£
Promon×êÑÐÈËÔ±·¢ÏÖÁËAndroidÖеÄÒ»¸öеÄÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-0096£©£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ʹ¶ñÒâÀûÓüÙ×°³É´óÎÞÊýºÏ·¨ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬²¢´ÓAndroidÓû§ÄÇÀïÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸ÷ì϶Óë¸Ã¹«Ë¾ÓÚ2019Äê·¢ÏֵijôÃûÔ¶ÑïµÄStrandHogg·ì϶ÀàËÆ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø±»Promon¶¨ÃûΪStrandHogg 2.0¡£¡£¡£¡£¡£¡£¡£
Strandhogg 2.0ÊÇͨ¹ý·´ÉäÖ´Ðе쬣¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¶ñÒâÀûÓÃ×ÔÓɵؼٶ¨ºÏ·¨ÀûÓõÄÉí·Ý£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ò²Î¬³ÖÆëÈ«°µ²Ø¡£¡£¡£¡£¡£¡£¡£Ò»µ©É豸ÉÏ×°ÖÃÁ˶ñÒâÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»½Ó¼û¸öÈËSMSÐÂÎźÍÕÕÆ¬£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Êܺ¦ÕߵĵǼʹ´¦£¬£¬£¬£¬£¬£¬£¬£¬¸ú×ÙGPSÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬£¬¼Í¼µç»°¶Ô»°ÒÔ¼°Í¨¹ýµç»°µÄÉãÏñÍ·ºÍÂó¿Ë·ç½øÐмäµý»î¶¯¡£¡£¡£¡£¡£¡£¡£
É豸ÉÏ×°ÖõĶñÒâÀûÓ÷¨Ê½Äܹ»¹¥»÷²¢ºýŪÓû§£¬£¬£¬£¬£¬£¬£¬£¬ÔÚµ¥»÷ºÏ·¨ÀûÓ÷¨Ê½µÄͼ±êʱ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÓû§ÆÁÄ»ÉÏÏÔʾ¶ñÒâ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÊܺ¦ÕßËæºóÔڴ˽çÃæÖÐÊäÈëÆäµÇ¼ʹ´¦£¬£¬£¬£¬£¬£¬£¬£¬ÔòÕâЩÃô¸Ð¾ßÌåÐÅÏ¢½«Á¢¼´·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£
ͨ¹ýÀûÓÃStrandHogg 2.0£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß²»±ØÒªroot½Ó¼ûȨÏÞ»òÉ豸µÄÈκÎȨÏÞ¼´¿ÉÖ´Ðи÷Àà¶ñÒ⹤×÷£¬£¬£¬£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º
? ͨ¹ýÂó¿Ë·çÊÕÌýÓû§
? ͨ¹ýÏà»úÅÄÕÕ
? ÔĶÁºÍ·¢ËÍSMSÐÂÎÅ
? ¼Í¼µç»°¶Ô»°
? ÍøÂç´¹µöµÇ¼ʹ´¦
? ½Ó¼ûÉ豸ÉÏËùÓиöÈËÕÕÆ¬ºÍÎļþ
? »ñÈ¡µØÎ»ºÍGPSÐÅÏ¢
? ½Ó¼ûÁªÏµÈËÁбí
? ½Ó¼ûµç»°ÈÕÖ¾
GoogleÒÑÓÚ2019Äê12ÔÂÊÕµ½¸Ã·ì϶µÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2020Äê4ÔÂÏòAndroidÉú̬ϵͳºÏ×÷ͬ°éÍÆ³öÁ˲¹¶¡·¨Ê½ºó£¬£¬£¬£¬£¬£¬£¬£¬ÒѾÕë¶ÔAndroid 8.0¡¢8.1ºÍ9°æ±¾°ä²¼Á˰²È«½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£
PromonÊ×ϯ¼¼Êõ¹Ù¼æÊ×´´ÈËÌÀÄ·¡¤À³ÈûÃ×Èû¡¤ººÉ£¨Tom Lysemose Hansen£©°µÊ¾£º¡°AndroidÓû§Ó¦¾¡¿ì½«ÆäÉ豸¸üе½×îй̼þ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»£»¤×Ô¼ºÃâÊÜʹÓÃStrandHogg 2.0µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡±
ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬£¬£¬£¬»¹Ã»Óз¢ÏÖ¶ñÒâÈí¼þ»ý¼«ÀûÓÃÒ°±í°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£
PromonÔ¤²â£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«Í¬Ê±Ê¹ÓÃStrandHoggºÍStrandHogg 2.0£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâÁ½¸ö·ì϶¶¼ÒÔ¹ÖÒìµÄ·½Ê½ÒÔ·ÖÆçµÄ·½Ê½¹¥»÷É豸¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¾ø´óÎÞÊýÓû§ÈÔÔÚÆäÉ豸ÉÏÔËÐÐAndroid 9.0»ò¸üÔç°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý90£¥µÄAndroidÓû§ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://source.android.com/security/bulletin/2020-05-01
0x03 ÓйØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/critical-android-bug-lets-malicious-apps-hide-in-plain-sight/
0x04 ²Î¿¼Á´½Ó
https://promon.co/strandhogg-2-0/
https://source.android.com/security/bulletin/2020-05-01
0x05 ¹¦·òÏß
2020-05-26 Promon×êÑÐÈËÔ±°ä²¼²¼¸æ
2020-05-27 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ