• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Nearly 1 billion phones can be hacked with 1 text

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
July 27, 2015, 3:01 PM ET

So listen: Can I have your number?

Can I have it? Can I? Have it?

Um…maybe not. Actually, you should think twice before giving away your cell phone number—especially if you happen to own a phone that runs on Google’s Android operating system.

That’s the only thing a hacker needs to compromise a handset.

A mobile security researcher has uncovered a flaw that leaves as many as 95% of Android devices—that’s 950 million gadgets—exposed to attack. The computer bug, nicknamed “Stagefright” after a vulnerable media library in the operating system’s open source code, may be one of the worst Android security holes discovered to date. It affects Android versions 2.2 and on.

Should a hacker learn someone’s cell phone number, all it takes is for that person to send a malware-laced Stagefright multimedia message to an affected phone in order to steal its data and photos or to hijack its microphone and camera, among other nefarious actions. Worse yet, a user might have no idea that his or her device has been compromised.

Joshua Drake, vice president of research and exploitation at the mobile security firm Zimperium zLabs, says an attacker can delete the message before a victim has any idea.

 

“These vulnerabilities are extremely dangerous because they do not require that the victim take any action to be exploited,” he writes on his company’s blog. “Unlike spear-phishing, where the victim needs to open a PDF file or a link sent by the attacker, this vulnerability can be triggered while you sleep. Before you wake up, the attacker will remove any signs of the device being compromised and you will continue your day as usual – with a trojaned phone.”

When Drake reported the severe vulnerabilities along with potential fixes to Google (GOOG) in April (as well as another set May), the company, he writes, “acted promptly and applied the patches to internal code branches within 48 hours.” That doesn’t mean the problem is resolved, however.

As Forbes reporter Thomas Fox-Brewster writes, device manufacturers will still need to push the updates out in order to safeguard their customers. Google’s major Android partners, which include phone-makers like LG, Lenovo (LNVGY), Motorola, Samsung (SSNLF), and Sony (SNE) were not immediately available to comment. (Fortune has reached out to these handset makers. We will update this when we hear back.)

An HTC (HTC) spokesperson responded: “Google informed HTC of the issue and provided the necessary patches, which HTC began rolling into projects in early July. All projects going forward contain the required fix.”

Drake praises the security firm Silent Circle, based in Geneva, Switz., which makes the Blackphone handset, for its quick response protecting users since it released PrivatOS version 1.1.7. He also praises Mozilla, maker of the Firefox web browser, for including fixes since version 38. “We applaud these vendors for prioritizing security and releasing patches for these issues quickly.”

[fortune-brightcove videoid=4177674506001]

 

“This is Heartbleed for mobile,” said Chris Wysopal, chief tech and information security officer at the application security firm Veracode. These vulnerabilities “are exceedingly rare and pose a serious security issue for users since they can be impacted without having clicked on a link, opened a file or opened an SMS.”

Drake plans to present his research at the Black Hat and Def Con security conferences in Las Vegas next month.

So, um, can I have your number?

Update July 27, 2015 — Google told Fortune:

We thank Joshua Drake for his contributions. The security of Android users is extremely important to us and so we responded quickly and patches have already been provided to partners that can be applied to any device.

Most Android devices, including all newer devices, have multiple technologies that are designed to make exploitation more difficult. Android devices also include an application sandbox designed to protect user data and other applications on the device.

Update July 28, 2015 —

Google Nexus told Fortune:

As part of a regularly scheduled security update, we plan to push further safeguards to Nexus devices starting next week. And, we’ll be releasing it in open source when the details are made public by the researcher at BlackHat.

(You can read more about Android security from Adrian Ludwig, Google’s lead Android security engineer, here.)

Samsung told Fortune:

Protecting our consumers’ privacy is our top priority, and we work hard every day to safeguard our valued Samsung users. Google notified us about the issue, and we are working to roll-out the software update as soon as possible. Samsung encourages users to keep their software and apps updated, and to exercise caution when clicking on an unsecure mail or link.

 

Motorola told Fortune:

After Google informed us in late June, we’ve been working to integrate, test and deploy the patches. It has been included in many of our recent Lollipop upgrades for current products and we’ll include it in the remaining planned Lollipop upgrades as soon as possible. All of our products being announced on July 28 will have the patch integrated into the software.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Elon Musk, wearing all black and in front of a blue background, presses his hands together.
Big TechDavos
Elon Musk makes the case for why his $2.2 trillion tech empire is the only way to save humanity as the only intelligent life in the universe
By Sasha RogelbergJanuary 22, 2026
13 hours ago
sternfels
CommentaryConsulting
AI makes human intelligence more important, not less 
By Bob Sternfels and Lucy PerezJanuary 22, 2026
18 hours ago
Building with a Deloitte company sign
Future of WorkConsulting
Deloitte to scrap traditional job titles as AI ushers in a ‘modernization’ of the Big Four
By Jake AngeloJanuary 22, 2026
18 hours ago
NewslettersEye on AI
OpenAI’s former head of sales is entering VC. She still calls herself an ‘AGI sherpa’
By Sharon GoldmanJanuary 22, 2026
19 hours ago
David Sacks gestures during a speech outside the White House
AITech
America could ‘lose the AI race’ because of too much ‘pessimism,’ White House AI czar David Sacks says
By Tristan BoveJanuary 22, 2026
19 hours ago
Elon Musk, in front of a blue "World Economic Forum" background, puts his hand to his mouth.
EnergyDavos
Elon Musk warns the U.S. could soon be producing more chips than we can turn on. And China doesn’t have the same issue
By Sasha RogelbergJanuary 22, 2026
19 hours ago

Most Popular

placeholder alt text
Economy
'Some form of crisis is almost inevitable': The $38 trillion national debt will soon be growing faster than the U.S. economy itself, watchdog warns
By Nick LichtenbergJanuary 22, 2026
18 hours ago
placeholder alt text
Success
Nvidia CEO Jensen Huang says ‘a lot’ of six-figure jobs in plumbing and construction are about to be unlocked because someone needs to build all these new AI centers
By Preston ForeJanuary 21, 2026
2 days ago
placeholder alt text
Politics
Jamie Dimon tells Davos: ‘You didn’t do a particularly good job making the world a better place’
By Eleanor PringleJanuary 21, 2026
2 days ago
placeholder alt text
Energy
Elon Musk warns the U.S. could soon be producing more chips than we can turn on. And China doesn’t have the same issue
By Sasha RogelbergJanuary 22, 2026
19 hours ago
placeholder alt text
Economy
Jamie Dimon says he’d have no issue paying higher taxes if it actually went to people who need it. Right now it just goes to the Washington ‘swamp’
By Eleanor PringleJanuary 21, 2026
2 days ago
placeholder alt text
Success
McDonald’s CEO shares tough love career advice he’d give Gen Z and young millennial workers: ‘No one cares about your career’
By Orianna Rosa RoyleJanuary 22, 2026
21 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.