• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

2

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

3

Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics

1

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

2

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

3

Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
Techstagefright

Stagefright is back: More than 1 billion phones can be hacked with 1 video or song

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
October 1, 2015, 11:56 AM ET
Google's Android mobile OS.
Google's Android mobile OS.Photograph by Bloomberg via Getty Images

It’s time to evacuate the Android dance floor—lest you be infected by the sound.

Two new critical vulnerabilities in Google’s mobile operating system announced by security researchers on Thursday put more than a billion Android devices at risk of being hacked. That means “almost every Android device” is affected, ranging from Android version 1.0 to the latest version 5.0, also known as “lollipop,” the researcher said.

Attackers can exploit these computer bugs by tricking users into visiting websites that host malicious MP3 or MP4 files. Once a victim previews one of these infected multimedia files, which commonly package music or video, that person’s machine can swiftly be compromised. The issue involves how Android processes these files’ metadata through a media playback engine named Stagefright.

This is not the first time that researchers have found this portion of Android’s code to be massively vulnerable. Zimperium zLabs, the mobile security firm that discovered the flaws, disclosed a set of seven monumental Stragefright bugs earlier this year. Those vulnerabilities could have enabled hackers to hijack as many as 950 million Android devices through a single infected multimedia text message.

Like the first set of Stagefright bugs, the latest couple—dubbed “Stagefright 2.0” by the researchers—allows attackers to take control of a compromised device and to access its data, photos, camera, and microphone. Taken together, the new issues are even more pervasive as they affect more devices.

The first of the new bugs—labeled CVE-2015-6602—affects nearly every Android device released since the first generation of the software debuted in 2008. The second bug—CVE-2015-3876—impacts versions 5.0 and up, and makes the problems easier to trigger.

Fortune spoke to Zuk Avraham, founder and chairman of Zimperium, about the firm’s findings. Although he withheld certain information (to prevent others from taking advantage of the bugs), he did compare them to the first generation Stagefright flaws. “It’s as critical a vulnerability,” he said. “It can do the same kind of damage.”

Since Google (GOOG) has, as a result of the first Stagefright disclosures, patched the mechanism in its Hangouts and Messenger apps by which Android automatically processed media files upon receipt, that means exploiting Stagefright 2.0 requires a different tactic. Simply sending an infected MP3 or MP4 filed to a victim will not immediately detonate its payload. Instead, the attacker must trick a recipient into either viewing a video or listening to a song via a compromised network, through a web browser, or through a vulnerable instant messenger, media player, or other third-party app.

Avraham added that his team had not invested the time to determine which apps and media players in particular might be vulnerable, since many of these are vendor or carrier-specific and would have taken too long given the variety of applications within the fragmented Android manufacturing ecosystem. Android devices of the version 5.0 and above, however, don’t need the additionally vulnerable apps, he said. These devices instead can be “hacked out of the box.”

Joshua Drake, who headed research on this project as well as the prior work, disclosed the bugs to Google on August 15. “These issues are equally exploitable as the original Stagefright issues,” Drake told Fortune via email, passed along by a spokesperson. They “have been assigned a critical rating by the Android Security Team under the following clause,” he continued, pointing to an Android security resources page that contains severity ratings.

Under “critical” one finds the following: “Remote privileged code execution (execution at a privilege level that third-party apps cannot obtain.” That’s the bucket Stagefright 2.0 falls under.

A Google spokesperson told Fortune via email that the company already has patches in the queue. “As announced in August, Android is using a monthly security update process,” the spokesperson said, referencing the company’s decision to release fixes on a more regular schedule in the wake of the first Stagefright disclosures. “Issues including the ones Zimperium reported, will be patched in the October Monthly Security Update for Android rolling out Monday, October 5th and will be posted about here.”

That means patches will be publicly available for the company’s Nexus devices starting Oct. 5th. The spokesperson told Fortune that the company provided fixes to its Android manufacturing partners and carriers on Sept. 10, and that it is working with those companies “to deliver updates as soon as possible.” Attacks exploiting the bugs have not yet been reported in the wild, the spokesperson said.

Fortune is still waiting to learn when Android’s partnering phone manufacturers plan to roll out their patches. We will update this story when we hear back.

You can find out whether your device is vulnerable using Zimperium’s Stagefright detector app, which is available in the Google Play store. In the meantime, be extra cautious of the media you download. Stop these beats from killing you.

Do not—I repeat, do not—let the music take you underground.

For more on Stagefright, watch this video below.

 

Subscribe to Data Sheet, Fortune’s daily business-tech newsletter.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Samuel Corum/Getty Images
Big TechSpaceX
Elon Musk’s proposed pay package in SpaceX’s IPO filing reveals what the company actually is: a $1 trillion monster built to colonize Mars
By Eva RoytburgMay 20, 2026
7 hours ago
elon
SuccessIPOs
SpaceX IPO targets $28.5 trillion total addressable market, mission to ‘make life multiplanetary’ and understand ‘true nature of the universe’
By Nick LichtenbergMay 20, 2026
9 hours ago
Jensen Huang, chief executive officer of Nvidia
AINvidia
Nvidia tells skeptical investors that AI is ready to go mainstream
By Ian King and BloombergMay 20, 2026
9 hours ago
SpaceX finally files IPO prospectus, reveals revenue is up–but losses are too
Big TechSpaceX
SpaceX finally files IPO prospectus, reveals revenue is up–but losses are too
By Allie Garfinkle and Alexei OreskovicMay 20, 2026
9 hours ago
Elon Musk sits with his fists together, looking up.
Commentaryspace
SpaceX will be worth trillions, but the space station that made it possible is worth even more — if we don’t squander it
By Tejpaul BhatiaMay 20, 2026
10 hours ago
Antler CEO Magnus Grimeland says Silicon Valley doesn’t have a monopoly on tech: ‘People can innovate from almost anywhere’
AsiaAsia Agenda
Antler CEO Magnus Grimeland says Silicon Valley doesn’t have a monopoly on tech: ‘People can innovate from almost anywhere’
By Angelica AngMay 20, 2026
10 hours ago

Most Popular

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Workplace Culture
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
By Preston ForeMay 19, 2026
1 day ago
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
Success
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
By Preston ForeMay 20, 2026
16 hours ago
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
Future of Work
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
By Mike Householder and The Associated PressMay 17, 2026
4 days ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
8 days ago
Dr. Bernice King on why companies that walked back DEI were never truly committed: 'If you retreat that quick…that reveals who you really are'
Workplace Culture
Dr. Bernice King on why companies that walked back DEI were never truly committed: 'If you retreat that quick…that reveals who you really are'
By Preston ForeMay 19, 2026
1 day ago
Current price of oil as of May 20, 2026
Personal Finance
Current price of oil as of May 20, 2026
By Joseph HostetlerMay 20, 2026
17 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.