CVE-2020-0096 | Android ÌØÈ¨ÌáÉý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-27

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-0096

ʱ    ¼ä

2020-05-27

Àà    ÐÍ

EOA

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Android <= 9.0



0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



AndroidÊÇÃÀ¹ú¹È¸è£¨Google£©ºÍÅ­°ÕÐݳÖÉ豸ÁªÃË£¨¼ò³ÆOHA£©µÄÒ»Ì×ÒÔLinuxΪ»ù´¡µÄ¿ªÔ´²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£FrameworkÊÇÆäÖеÄÒ»¸öAndroid¿ò¼Ü×é¼þ¡£¡£¡£¡£¡£¡£¡£

Promon×êÑÐÈËÔ±·¢ÏÖÁËAndroidÖеÄÒ»¸öеÄÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-0096£©£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã·ì϶ʹ¶ñÒâÀûÓüÙ×°³É´óÎÞÊýºÏ·¨ÀûÓ㬣¬ £¬£¬£¬£¬£¬£¬²¢´ÓAndroidÓû§ÄÇÀïÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸ÷ì϶Óë¸Ã¹«Ë¾ÓÚ2019Äê·¢ÏֵijôÃûÔ¶ÑïµÄStrandHogg·ì϶ÀàËÆ£¬£¬ £¬£¬£¬£¬£¬£¬Òò¶ø±»Promon¶¨ÃûΪStrandHogg 2.0¡£¡£¡£¡£¡£¡£¡£

Strandhogg 2.0ÊÇͨ¹ý·´ÉäÖ´ÐеÄ£¬£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¶ñÒâÀûÓÃ×ÔÓɵؼٶ¨ºÏ·¨ÀûÓõÄÉí·Ý£¬£¬ £¬£¬£¬£¬£¬£¬Í¬Ê±Ò²Î¬³ÖÆëÈ«°µ²Ø¡£¡£¡£¡£¡£¡£¡£Ò»µ©É豸ÉÏ×°ÖÃÁ˶ñÒâÀûÓ㬣¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»½Ó¼û¸öÈËSMSÐÂÎźÍÕÕÆ¬£¬£¬ £¬£¬£¬£¬£¬£¬ÇÔÈ¡Êܺ¦ÕߵĵǼʹ´¦£¬£¬ £¬£¬£¬£¬£¬£¬¸ú×ÙGPSÒÆ¶¯£¬£¬ £¬£¬£¬£¬£¬£¬¼Í¼µç»°¶Ô»°ÒÔ¼°Í¨¹ýµç»°µÄÉãÏñÍ·ºÍÂó¿Ë·ç½øÐмäµý»î¶¯¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



É豸ÉÏ×°ÖõĶñÒâÀûÓ÷¨Ê½Äܹ»¹¥»÷²¢ºýŪÓû§£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚµ¥»÷ºÏ·¨ÀûÓ÷¨Ê½µÄͼ±êʱ£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚÓû§ÆÁÄ»ÉÏÏÔʾ¶ñÒâ°æ±¾£¬£¬ £¬£¬£¬£¬£¬£¬ÈôÊÇÊܺ¦ÕßËæºóÔڴ˽çÃæÖÐÊäÈëÆäµÇ¼ʹ´¦£¬£¬ £¬£¬£¬£¬£¬£¬ÔòÕâЩÃô¸Ð¾ßÌåÐÅÏ¢½«Á¢¼´·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ͨ¹ýÀûÓÃStrandHogg 2.0£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß²»±ØÒªroot½Ó¼ûȨÏÞ»òÉ豸µÄÈκÎȨÏÞ¼´¿ÉÖ´Ðи÷Àà¶ñÒ⹤×÷£¬£¬ £¬£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º

? ͨ¹ýÂó¿Ë·çÊÕÌýÓû§

? ͨ¹ýÏà»úÅÄÕÕ

? ÔĶÁºÍ·¢ËÍSMSÐÂÎÅ

? ¼Í¼µç»°¶Ô»°

? ÍøÂç´¹µöµÇ¼ʹ´¦

? ½Ó¼ûÉ豸ÉÏËùÓиöÈËÕÕÆ¬ºÍÎļþ

? »ñÈ¡µØÎ»ºÍGPSÐÅÏ¢

? ½Ó¼ûÁªÏµÈËÁбí

? ½Ó¼ûµç»°ÈÕÖ¾

GoogleÒÑÓÚ2019Äê12ÔÂÊÕµ½¸Ã·ì϶µÄ֪ͨ£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÓÚ2020Äê4ÔÂÏòAndroidÉú̬ϵͳºÏ×÷ͬ°éÍÆ³öÁ˲¹¶¡·¨Ê½ºó£¬£¬ £¬£¬£¬£¬£¬£¬ÒѾ­Õë¶ÔAndroid 8.0¡¢8.1ºÍ9°æ±¾°ä²¼Á˰²È«½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£

PromonÊ×ϯ¼¼Êõ¹Ù¼æÊ×´´ÈËÌÀÄ·¡¤À³ÈûÃ×Èû¡¤ººÉ­£¨Tom Lysemose Hansen£©°µÊ¾£º¡°AndroidÓû§Ó¦¾¡¿ì½«ÆäÉ豸¸üе½×îй̼þ£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔ±£»£» £»£»£»£»£»¤×Ô¼ºÃâÊÜʹÓÃStrandHogg 2.0µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡±

ÐÒÔ˵ÄÊÇ£¬£¬ £¬£¬£¬£¬£¬£¬µ½Ä¿Ç°ÎªÖ¹£¬£¬ £¬£¬£¬£¬£¬£¬»¹Ã»Óз¢ÏÖ¶ñÒâÈí¼þ»ý¼«ÀûÓÃÒ°±í°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£

PromonÔ¤²â£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß½«Í¬Ê±Ê¹ÓÃStrandHoggºÍStrandHogg 2.0£¬£¬ £¬£¬£¬£¬£¬£¬ÓÉÓÚÕâÁ½¸ö·ì϶¶¼ÒÔ¹ÖÒìµÄ·½Ê½ÒÔ·ÖÆçµÄ·½Ê½¹¥»÷É豸¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¾ø´óÎÞÊýÓû§ÈÔÔÚÆäÉ豸ÉÏÔËÐÐAndroid 9.0»ò¸üÔç°æ±¾£¬£¬ £¬£¬£¬£¬£¬£¬³¬¹ý90£¥µÄAndroidÓû§ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://source.android.com/security/bulletin/2020-05-01


0x03 ÓйØÐÂÎÅ


https://www.bleepingcomputer.com/news/security/critical-android-bug-lets-malicious-apps-hide-in-plain-sight/


0x04 ²Î¿¼Á´½Ó


https://promon.co/strandhogg-2-0/

https://source.android.com/security/bulletin/2020-05-01


0x05 ¹¦·òÏß


2020-05-26 Promon×êÑÐÈËÔ±°ä²¼²¼¸æ

2020-05-27 VSRC°ä²¼·ì϶¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website