LAS VEGAS—Hundreds of Android devices will get updates to combat the Stagefright vulnerability in what might be the world's largest software update, Google's lead engineer for Android Security, Adrian Ludwig, said here at Black Hat.
With Stagefright, the way Android processes video files sent via text message could allow attackers to execute code on your device, simply by sending you a text message. It was discovered by researcher Josh Drake and named after the section of code that contains the vulnerability.
While Google's Ludwig had a lot to say about the state of Android security, much of it was in the context of Stagefright. 'It is the case that nearly all Android devices had a vulnerability,' he confirmed.
Google is currently updating all Nexus devices to address the Stagefright vulnerability, he said. Other device manufacturers are also following Google's lead and working to push out Google's patch to their customers. Ludwig called it 'the single largest unified software update the world has ever seen.' And given that there are 1 billion estimated Android users, he might be right.
'Hundreds of millions of devices will be updated in the next few days,' said Ludwig. That's especially welcome news because Drake submitted patches when he disclosed the vulnerability to Google. It was expected that those patches would take many more weeks to find their way to users who don't use Nexus phones, potentially leaving millions without the means to protect themselves from Stagefright.
How vulnerabilities help shape security features and mitigations in. Galaxy S7 Edge 1 1 1. Stagefright after patch v1, sanitized. Do you have any idea when the unbranded variants of the S7 (SM-G930U) & S7 edge (SM-G935U) will be getting the update to Android 8.0 Oreo!? Build Number: NRD90M.G930UUEU4BRD1. OS: Android 7.0. Security Patch: 2018Apr01.
All Nexus devices and these will receive Stage fright updates says Ludwig. #BHUSApic.twitter.com/xXuK1PNNvB
— Max Eddy (@wmaxeddy) August 5, 2015Though he was emphasizing the effort taken by Google and its Android partners to patch Stagefright, Ludwig admitted that Google could have done more. 'As an industry, we've looked over the events of the last few days and weeks,' he said. 'We need to move faster and we need to tell people what we are doing.'
To that end, Ludwig announced that Google would provide monthly security updates and service bulletins. Samsung and LG, said Ludwig, have made similar commitments.
'We're in the midst of the largest software update the world has ever seen,' said Ludwig. 'Until next month, when we do it again.'
A Diverse Environment
Throughout his presentation, Ludwig frequently returned to the idea that—contrary to popular belief—the diversity of Android made it safer. Commentators, this author, and others at PCMag have held that the fragmented nature of Android means that it is hard to push security updates. Prior to Black Hat, the estimation on the number of distinct Android devices rose to well over 24,000.
But Ludwig countered that the diversity of Android means that the ecosystem as a whole is stronger because every exploit requires customization to work across Android devices. 'Crop blights happen because everything is the same,' he said.
Ludwig said something similar at the 2014 RSA Conference. 'A single gold master with a bug affects hundreds of million of users,' he said at the time. 'There is no single gold master [for Android], every device is built from source that differs.'
How To Stagefright Android Phone
- Annual Android Upgrades? Yeah, Right
In a separate presentation at Black Hat, Drake disagreed with this conclusion. 'Diversity in the ecosystem complicates research, but it's not a barrier to exploitation,' he said.
The State of the Union
Though Stagefright cast a long shadow over Ludwig's talk, and Black Hat in general, he had much to say on the subject of Android security. The talk was among the highest profile of the conference, taking place immediately after the keynote and in the same location. It was styled as a State of the Union speech, and Ludwig maintained that the state of Android security was strong.
Ludwig took care to acknowledge the work of the security industry and researchers. He also discussed the behind-the-scenes protections that Google provides. Google Play, for example, has given Google enormous insight into app development, allowing the company to better evaluate the risks of particular apps. Ludwig called Verified Apps, a service which evaluates apps that are installed to Android devices from outside Google Play, 'the world's largest antivirus service. A billion devices checking with Google to see if an app is safe.'
He also mentioned Safety Net, an intrusion-detection system that monitors high-risk devices. According to Ludwig, around 200 million devices checked in with Safety Net, and only around half a percent had something harmful. Despite that impressive number, Ludwig said that Google never expects to reach zero because of the size of the Android ecosystem. 'Someone will always write something,' he said.
+ Operating System for Android Lollipop
Installation Requirements
Please refer to the release notes.
Versions
+
LifeGuard Update 03
Release Date:
July 2019
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
CFE-MC32-L-XX-010904-N-00-03.zipLifeGuard Update 03 (released 2-Jul-2019)
Download 57 MB+
LifeGuard Update 02
Release Date:
March 2019
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
CFE-MC32-L-XX-010904-N-00-02.zipLifeGuard Update 02 (released 19-Mar-2019)
Download 13 MB+
LifeGuard Update 01
Release Date:
January 2019
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
CFE-MC32-L-XX-010904-N-00-01.zipLifeGuard Update 01 (released 11-Jan-2019)
Download 12 MB+
Full Image
Release Date:
January 2019
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
M32N0LXXXAE0000001.apfEnterprise Reset MSP package (Erases Data Partition)
Download 366 KB M32N0LXXXAF0000001.apfFactory Reset MSP package (Erases Data & Enterprise Partitions)
Download 366 KB M32N0LXXXAUXX10904.apfMSP Full package update for L to L (Use this package for re-flashing the MC32N0 Lollipop device)
Download 251 MB M32N0LXXXRE0000001.zipEnterprise Reset package (Erases Data Partition)
Download 366 KB M32N0LXXXRF0000001.zipFactory Reset (Erases Data & Enterprise partitions)
Download 366 KB M32N0LXXXRUXX10904.zipFull Package Update for L to L (Use this package for re-flashing the MC32N0 Lollipop device)
Download 251 MB MC32N0LADL2JB0006.apfMSP downgrade package from L to JB (Use this package for downgrading MC32N0 device from Lollipop to Jelly Bean BSP v00006)
Download 154 MB MC32N0LAUJB2L10904.apfMSP Full package for JB to L Upgrade (Use this package for upgrading MC32N0 device from Jelly Bean to Lollipop)
Download 251 MB MC32N0LRDL2JB0006.zipRecovery downgrade package from L to JB (Use this package for downgrading MC32N0 device from Lollipop to Jelly Bean BSP v00006)
Download 154 MB MC32N0LRUJB2L10904.zipFull Package for JB to L Upgrade (Use this package for upgrading MC32N0 device from Jelly Bean to Lollipop)
Download 251 MB+ Operating System for Android JellyBean
Installation Requirements
Please refer to the release notes.
Versions
+
Full Image
Release Date:
March 2018
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
MC32N0JXXXAEEN0006.apfMSP Enterprise reset package
Download 142 KB MC32N0JXXXAUEN0006.apfOS update package for deployment using MSP
Download 155 MB MC32N0JXXXREEN0006.zipRecovery mode Enterprise reset package
Download 141 KB MC32N0JXXXRFEN0006.zipRecovery mode Factory reset package
Download 141 KB MC32N0JXXXRUEN0006.zipOS Recovery update package contained in a ZIP file
Download 155 MB+
Update 00.02
Release Date:
January 2018
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
CFE-MC32N0-J-xx-00005-x-00-02.zipUpdate 00.02 (released 18-Jan 2018)
Download 6 MB+
Update 00.01
Release Date:
July 2017
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
+
Full Image
Release Date:
April 2017
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
MC32N0JXXXAEEN00005.apfMSP Enterprise reset package
Download 142 KB MC32N0JXXXAUEN00005.apfOS update package for deployment using MSP
Download 154 MB MC32N0JXXXREEN00005.zipRecovery mode Enterprise reset package
Download 141 KB MC32N0JXXXRFEN00005.zipAndroid S7 Video Upload
Recovery mode Factory reset package
Download 141 KB MC32N0JXXXRUEN00005.zipOS Recovery update package contained in a ZIP file
Download 154 MB+
Full Image
Release Date:
May 2016
Device Compatibility
This software has been approved for use with the following devices:How To Turn Off Developer Mode On Android S7
- - MC3200 Mobile Computer
Documentation
Software
+
Update 00.01
Release Date:
July 2016
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
CFE-MC32N0-J-xx-112214-x-00-01.zipHotFix CFE v00.01
Download 5 MB+
Full Image
Release Date:
December 2014
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
MC32N0JXXXAEEN00003.apfMSP Enterprise reset package
Android S7 Smart Watch
Download 142 KB MC32N0JXXXREEN00003.zipRecovery mode Enterprise reset package
Download 141 KB MC32N0JXXXRFEN00003.zipRecovery mode Factory reset package
Download 141 KB MC32N0JXXXRUEN00003.zipRecovery OS Update Package
Download 143 MB+
Stagefright Update
Release Date:
July 2015
Device Compatibility
This software has been approved for use with the following devices:- - MC3200 Mobile Computer
Documentation
Software
Android Stagefright Exploit Code
SPR28147_MC32JBxxen112214_v2.apfMC32N0 JB Stagefright patch AirBEAM package
Download 1 MB SPR28147_MC32_JB_xx_en_112214_v2.zipWhat Is Stagefright Android
MC32N0 JB Stagefright recovery update patch
Download 1 MBFor maximum uptime and availability, we can help your business ensure its Zebra mobile computers, bar code scanners, RFID devices and wireless LAN (WLAN) infrastructure are online and ready for business.
Android S7 Phone
Zebra offers repair services for products that are under warranty, covered by a service contract or through a time-and-material-based charge.