Android phones can get infected by simply receiving a picture via message message, according to research released Monday.

This is most likely the best smartphone flaw ever before discovered. That affects an estimated 950 million phones worldwide -- about 95% the the Androids in use today.

The difficulty stems indigenous the method Android phones analyze incoming text messages. Even before you open a message, the phone instantly processes incoming media files -- including pictures, audio or video. That method a malware-laden paper can start infecting the call as shortly as it"s received, follow Zimperium, a cybersecurity company that specializes in mobile devices.

If this sound familiar, that"s because this Android cons is somewhat favor the current Apple text hack.

yet in that case, a text post with just the right characters could frozen an iphone phone or pressure it to restart. This Android flaw is worse, because a hacker might gain finish control that the phone: wiping the device, accessing apps or secretly transforming on the camera.

In a statement come, Google (GOOGL) acknowledged the flaw. It assured the Android has ways the limiting a hacker"s access to different apps and also phone functions. However hackers have been able to conquer these restrictions in the past.

The bug affects any type of phone utilizing Android software program made in the last 5 years, follow to Zimperium. That consists of devices to run Android"s Froyo, Gingerbread, Honeycomb, ice Cream Sandwich, Jelly Bean, KitKat and also Lollipop iterations (Google name its Android versions alphabetically after ~ desserts).


Zimperium said it warned Google about the flaw on April 9 and even listed a fix. The firm claims Google comment the an extremely next day, assuring a patch would certainly be mutual with customers in the future.

Typically, in this situations, service providers are offered a 90-day grace duration to issue a fix. It"s a dominance even Google abides by as soon as it finds flaws in others" software.

yet it"s to be 109 days, and also a resolve still isn"t mostly available. That"s why Zimperium is now going public v the news.

The concern now is how easily Google will manage to deal with this because that everybody. If Apple have the right to push out updates to every iPhones, Google can"t.

Google is notorious for having a broken distribution system. Number of entities was standing in in between Google and also its users, and also they consistently slow down the release of brand-new software. There space phone carriers -- prefer AT&T (T) and Verizon (VZ) -- and makers of physical devices -- choose Samsung (SSNLF) -- every one of which must work together to concern software updates.

Google told it already sent a resolve to that is "partners." However, it"s unclear if any of them have started pushing that out to users themselves.

because that that very reason, Google newly put its own Nexus phones an initial in heat to get updates.

This might be a test instance that reflects why it"s so important to obtain updates quickly.

kris Wysopal is a longtime hacker and also now an executive, management at cybersecurity for sure Veracode. He dubbed this Android"s version of Heartbleed, the devastating an insect that put millions of computer system networks at severe risk last year.

"I"m interested to watch if Google come up v a means to update gadgets remotely," he said. "Unless they can do that, we have actually a huge disaster on ours hands."