
LG On-Screen Phone Security Bypass Vulnerability lets attackers bypass the authentication and control Android phone.
LG's Android smartphones are critically vulnerable. This recent vulnerability disclosure by a user with github handle "irsl", also included a PoC (Proof-of-Concept).
LG On-Screen Phone Security Bypass Vulnerability
According to the disclosure, LG's On-Screen Phone (OSP) application is open to a severe vulnerability (CVE-2014-8757) by which a malicious attacker is able to bypass the authentication phase of the network communication, and thus establish a connection to the On Screen Phone application without the owner's knowledge or consent. Once connected, the attacker could have full control over the phone even without physical access to it. The attacker needs only access to the same local network as the phone is connected to, for example via Wi-Fi. The vulnerability was first reported by SEARCH-LAB Ltd. in September 2014.
Proof of Concept
The Proof of Concept code was tested against G1 and G2 models.
This osp-discovery helper script listens for discovery broadcast messages of the official LG On Screen Phone application and answers them, so the application would believe a Phone running OSP is available locally.
The osp-proxy script excepts the official LG On Screen Phone application would connect to it, which is possible by running osp-discovery.pl.
What is LG On-Screen Phone application?
The LG On-Screen Phone application (OSP) makes it easy to access and control LGs Android smartphones through a PC. The connection can be established either by using an USB cable or wirelessly through Wi-Fi or Bluetooth. When attempting to connect to the phone via OSP, a popup dialog is displayed on the phone and it is to be confirmed and accepted by the owner. Once the channel is established, the screen contents of the device are being transmitted to the PC as a motion stream, mouse clicks on the PC are turned into touch events on the phone. By using OSP one can control an LG Smart Phone just like it was in their hands.
Mitigation
After successful reporting of the vulnerability by SEARCH-LAB Ltd. to LG, a patched version of the application is available and can be downloaded through LGs Update Center and/or will be available in form of Maintenance Release for some models. LG smartphone users should make sure to have at least version 4.3.010 of the On Screen Phone (OSP) application installed. Please note that when OSP is pre-installed, the device is vulnerable by default OSP is started automatically and cannot be disabled in Settings.
Users are required to update the application to revision 4.3.010 or newer through LG Update Center.