• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Android Bug Lets Hackers Attack a Phone Using Only an Image File

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
February 7, 2019, 5:50 PM ET

Hackers could sneak their way inside any Android phone or tablet by sending a malicious image file, according to the latest Android security bulletin released by Google.

While there isn’t a record of the attack actually happening in the wild, the vulnerability in Android versions 7.0 to 9.0 would give hackers “privileged access” to run malicious code on any Android device that had opened a malicious PNG image file.

Perhaps the scariest part of all? There’s probably no way people would know they had been targeted.

The Android security bulletin classified the threat as severe, “based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed.”

The update mentioned that there has been no record of hackers actually pulling off the attack. Google was also, of course, deliberately vague on the technical details of how to hack Android.

The vulnerability has since been patched. However, Kathy Wang, director of security at GitLab, said if black hat hackers had learned of it first, it could have had serious consequences for Android users.

“In particular, the arbitrary code execution vulnerability is very serious, and Android could potentially benefit from employing tighter controls on approved apps and their subsequent updates,” she said. “It is a difficult balance between having a fully open contributor ecosystem versus keeping the approval process controlled, as Apple iOS mandates.”

While a patch has been rolled out, people who used Android devices made by third party companies will want to exercise caution and make sure they’ve downloaded the latest software updates, since it usually takes longer for Android security updates to be rolled out by Google’s partners.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
North America
'I meant what I said in Davos': Carney says he really is planning a Canada split with the U.S. along with 12 new trade deals
By Rob Gillies and The Associated PressJanuary 28, 2026
2 days ago
placeholder alt text
Politics
The American taxpayer spent nearly half a billion dollars deploying federal troops to U.S. cities in 2025, CBO finds
By Nick LichtenbergJanuary 28, 2026
2 days ago
placeholder alt text
C-Suite
Jeff Bezos capped his Amazon salary at $80,000: ‘How could I possibly need more incentive?’
By Sydney LakeJanuary 28, 2026
2 days ago
placeholder alt text
C-Suite
Fortune 500 CEOs are no longer giving employees an A for effort. Now they want proof of impact
By Claire ZillmanJanuary 28, 2026
2 days ago
placeholder alt text
Investing
Jerome Powell got a direct question about the U.S. ‘losing credibility’ and the soaring price of gold and silver. He punted
By Eva RoytburgJanuary 29, 2026
20 hours ago
placeholder alt text
Personal Finance
Current price of silver as of Thursday, January 29, 2026
By Joseph HostetlerJanuary 29, 2026
20 hours ago

Latest in Tech

HealthScience
As billionaires chase immortality, this startup cofounded by a Harvard genetics professor gets FDA approval for the first partial de-aging human trial
By Marco Quiroz-GutierrezJanuary 30, 2026
1 hour ago
A man works on two computers while a coworker looks on in the background.
AIGen Z
Gen Z believes using AI is making their colleagues dumb and lazy, but may paradoxically see it as key to their own promotion, Wharton says
By Sasha RogelbergJanuary 30, 2026
2 hours ago
Big TechApple
Apple’s blowout Q1 results were a reminder of what makes the company so impressive—and why it’s floundering in AI
By Alexei OreskovicJanuary 29, 2026
8 hours ago
C-SuiteFortune 500: Titans and Disruptors of Industry
Pfizer CEO says he used ‘emotional blackmail’ to get employees to achieve impossible goals during COVID-19
By Eva RoytburgJanuary 29, 2026
10 hours ago
ICE
CybersecurityMilitary
Only 4 democracies have created paramilitary police squads since 1960—if you include ICE
By Erica De Bruin and The ConversationJanuary 29, 2026
12 hours ago
Claude 4 illustration
AIAnthropic
Top engineers at Anthropic, OpenAI say AI now writes 100% of their code—with big implications for the future of software development jobs
By Beatrice NolanJanuary 29, 2026
14 hours ago