Monday, 21 November 2022 06:03

Hackers found a way to unlock your Android phone without your password. This is what to do

Rate this item
(0 votes)

Your phone’s lock screen is supposed to be a safeguard against the world (and accidental unlocks in your pocket). When it’s locked, your phone can’t be opened without either the passcode, a face scan, or a fingerprint. If you lose your phone or someone snatches it from you, you can rest assured they won’t be able to do anything with it. Except right now they can, thanks to a recently discovered vulnerability allowing anyone to bypass an Android device’s lock screen.

As reported by Bleeping Computer, cybersecurity researcher David Schütz discovered a way to unlock both a Google Pixel 6 and Pixel 5 without needing to know the passcode. It happened after his Pixel 6 ran out of charge, and after he incorrectly entered his PIN wrong three times. His SIM card was then locked, so he entered the PUK (Personal Unblocking Key) to restore it.

However, once the SIM was recovered, the Pixel asked him to scan his fingerprint. That shouldn’t happen, since Pixels (as well as most phones) require you to enter the passcode in order to unlock after a reboot. You shouldn’t have the option to use your fingerprint to unlock the phone until after one successful unlock with the passcode.

From there, Schütz realized there was a legitimate security flaw here. If an attacker inserts their own SIM into a target’s Android, then enters the wrong SIM PIN three times, they can enter their SIM’s PUK to be able to create a new SIM PIN. Once they do, they bypass the lock screen entirely and access the phone.

Schütz brought this flaw to Google’s attention back in June of this year, but it took the company five months to finally push a patch. Still, it’s good there is a patch: It’s not clear how long this vulnerability was actually floating around, potentially putting millions of Androids in jeopardy.

How to fix the latest lock screen security flaw on Android

If you have a phone running Android 10, 11, 12, or 13, you need to install the November 2022 security update in order to patch this vulnerability. If you already installed the patch, you’re good to go! But otherwise, install it ASAP.

To install a security patch on Android, head to Settings > System > System Update, then allow the OS to look for a new update. If there’s one available, you can download and install it. You can also check for security updates from Settings > Security > Google Security checkup.

 

Lifehacker

May 20, 2024

Nigerian manufacturers still in business lament as goods pile up in warehouses due to poor…

Manufacturers of fast-moving consumer goods, FMCG are in dire agony over the continued rise in…
May 19, 2024

‘Nothing to it’: FG, Presidency dismiss Atiku, Obi’s proposed alliance against Tinubu in 2027 runs

The Federal Government has dismissed the proposed alliance between former Vice President Atiku Abubakar and…
May 14, 2024

These 3 phrases make you sound smarter and more emotionally intelligent, experts say

Sounding smart and emotionally intelligent isn't just about the idea you're trying to convey. How…
May 18, 2024

People are revealing the wild rumours that went around about ‘that one teacher’ in their…

Almost everyone can recall "that one teacher" from their school days who was involved in…
May 15, 2024

Bandits attack 50 communities in Zamfara, kill 49

Bello Hassan, a member of the House of Representatives representing Zurmi/Shinkafi Federal Constituency, reported on…
May 20, 2024

Here’s the latest as Israel-Hamas war enters Day 227

Airstrike kills 27 in central Gaza and fighting rages as Israel's leaders are increasingly divided…
May 19, 2024

Scientists develop device that can detect when someone is sarcastic

Experts have developed a device that can detect when someone is sarcastic It works by…
April 30, 2024

Finidi George is new Head Coach for Super Eagles

Former Nigerian winger Finidi George has been appointed as the head coach of the national…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2024 NewsScroll. All rights reserved.