It had to happen sooner or later. Now Kevin Beaumont (@GossiTheDog) reports on DoublePulsar that: Android has a feature called Android Debug Bridge (A
[See the full post at: Root Bridge – Android devices get pwned]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Root Bridge – Android devices get pwned
Home » Forums » Newsletter and Homepage topics » Root Bridge – Android devices get pwned
- This topic has 20 replies, 6 voices, and was last updated 6 years, 11 months ago.
Tags: Android Debug Bridge
AuthorTopicViewing 10 reply threadsAuthorReplies-
anonymous
Guest -
anonymous
Guest
-
anonymous
GuestJune 8, 2018 at 1:30 pm #196743Quick note, it says on the ADB page that you need to accept a certificate in order to allow ADB connections from specific devices as of 4.2.2 (Jellybean, 2013-ish). It also seems that you need to be in Developer mode now.
This mostly likely affects older Android-powered devices, and probably the cheap Chinese devices that aren’t certified to work with Google services. For consumer devices, consider flashing the ROM or replacing if it can’t run Jellybean or newer.
MrJimPhelps
AskWoody MVPJune 8, 2018 at 3:30 pm #196766I wonder how many Android-powered smart cars have been hacked through this vulnerability?
https://www.recode.net/2016/11/14/13601444/google-android-auto-automotive-car-tech
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file serveranonymous
GuestJan K.
AskWoody Loungeranonymous
GuestJune 8, 2018 at 5:05 pm #196779Related news article from Feb 2018 …
https://arstechnica.com/information-technology/2018/02/out-of-nowhere-currency-mining-botnet-infects-5000-android-devices/?comments=1I think most Android smartphones are not affected since ADB is disabled by default.
Also, … http://www.tinmith.net/wayne/blog/2015/11/android-remote-adb.htm
anonymous
GuestMicrofix
AskWoody MVPJune 9, 2018 at 3:40 am #196841IIRC android phones used to come with ‘Dev mode’ and ‘USB Debugging’ disabled at default otherwise the phone warranty was affected. When did this all change with google android?
I still use my Nokia mobile ‘dumb phone’. Great battery life and small enough to forget I have it in my pocket at times.
Windows - commercial by definition and now function...1 user thanked author for this post.
-
mindwarp
AskWoody PlusJune 9, 2018 at 8:58 pm #196978Dev mode doesn’t affect warranty status. I generally turn it and USB debugging on on my devices to use ADB to backup my nonrooted devices to my computer, when I’ve done major updates or had to replace a device (that backs up more for me than the inbuilt backup to Google Drive ever has).
1 user thanked author for this post.
-
anonymous
GuestJune 10, 2018 at 3:25 am #196999Android’s ADB is automatically disabled or turned off when not in use, eg after the USB adapter cord has been unplugged.
ADB disabled is the default setting.
Previous reported malware infection of Android devices via ADB was by connecting Android smartphones to malware-infested computers, Power-banks and other USB devices.
ADB is not vulnerable per se. -
mindwarp
AskWoody PlusJune 10, 2018 at 7:12 pm #197133You do still have to enable USB debugging on the Android device to run ADB on a computer to backup a device, which means enabling Dev Mode. That ties into the original comment, about doing so invalidating warranties, which it doesn’t. You’re not rooted just by doing that, after all. I did disable USB debugging and revoked certificates on my devices, and I’ll just have to remember to reenable it the next time I need to do a full scale backup like that.
1 user thanked author for this post.
-
-
anonymous
GuestJune 9, 2018 at 5:29 am #196842Unfortunately, vendors have been shipping products with Android Debug Bridge enabled. It listens on port 5555, and enables anybody to connect over the internet to a device.
During research for this article, we’ve found everything from fuel tankers in the US to DVRs in Hong Kong to mobile telephones in South Korea.
Sounds like the source of the problem is rogue vendors in China/East Asia, and not a vulnerability in Android = avoid buying no-name Android devices from China/East Asia.
About vulnerable DVRs in HK …
https://www.androidcentral.com/android-70-brings-better-dvr-features-and-picture-picture-android-tvanonymous
GuestJune 9, 2018 at 11:37 am #196865I wonder if the dangers inherent in the “everything is always connected” mindset will ever be recognized
1 user thanked author for this post.
mindwarp
AskWoody PlusJune 9, 2018 at 8:53 pm #196977Meh… what’s the problem?
When I power on my android device, it phones home to mothership and often gets updates.
Surely google has long time ago patched this?
Besides even if Google had already patched it, which there is no mention of that, that doesn’t mean Android OEMs have. Remember, that’s the current problem with the Android ecosystem – after Google comes up with a new build, then manufacturers have to come up with their own variants for each currently supported device, and THEN the ISPs have THEIR turn if a device is specificly locked to a carrier. Also, depending on how far back this issue goes, many affected devices may never be patched.
1 user thanked author for this post.
-
anonymous
GuestJune 10, 2018 at 3:26 am #197001Certain things still require operating system updates. Operating system-level features and support for new hardware standards can’t be rolled out in the background. They require new versions of the core operating system.
However, these updates are becoming less and less significant. Google is rolling out as many new features as possible via Play Services updates and app updates. They’re splitting out more and more apps from the Android operating system, making them available in Google Play so every device can update to them.
The reality is that Android updates are becoming less and less significant. If you have a device with Marshmallow (Android 6.0) or above, you still have a very modern Android experience with most of the latest features. You can still use all the latest apps because Google has given your device access to most of the latest APIs.
-
Jan K.
AskWoody LoungerJune 10, 2018 at 7:38 am #197036 -
anonymous
GuestJune 10, 2018 at 10:31 am #197046I use an Acer A3-A30 tablet and do get updates from google.
Since everything Google Play is deactivated, I can only assume updates are for system?Yes, the updates you’ve been getting directly from Google have been for the OS only, NOT the apps. Even with a fully updated OS, it’s still quite possible to get infected by a piece of crapware through a vulnerable program that hasn’t been updated.
Time to re-enable your Google Play services and Google Play Store so you can get updates for the apps in the store you may have on your tablet, such as Firefox or Chrome browser and whatever security application you may have, such as Lookout, for example. Those apps don’t get updated by Google when a security or other update for the OS is released.
Security apps should go out on their own and get their own definition or signature updates without the help of the Google Play store, but they won’t update themselves if there’s a program update or bug fix. Those get pushed out via the Google Play Store almost exclusively.
So, having a vulnerable browser will only get remedied by getting the revised browser version from the Google Play store. Same goes for whatever security/anti-crapware solution you have…the program updates only come through the Google Play store.
-
Jan K.
AskWoody LoungerJune 11, 2018 at 3:22 pm #197272Thanks.
I’m doomed! 😀
android is indeed version 5. Don’t have any apps from the store and my chrome browser has been rolled way back to the very old 57.02 version (last one with a decent bookmark handler…).
So my only defence is the updates google makes and my AdGuard filter (getting updates directly from them, not google)…
Well, it’ll have to do! Nobody can’t really do anything with this tablet as it’s after all only a gadget for browsing a.o. non-important stuff.
-
-
-
mindwarp
AskWoody PlusJune 10, 2018 at 7:26 pm #197140I just looked up your device. What was posted below about you getting updates for your OS as a whole from Google is incorrect. Check your settings – you should still be running Android 5.0 Lollipop, as Acer never released an upgrade to Android 6.0 Marshmallow for your device. Manufacturers vary widely on how long they support Android devices – the more you pay, the more likely you’ll get upgrades to two major versions, but that’s in the best case scenario – and Android comes out with a new major version every year. You are getting updates to Google apps via Play Services most likely, and that part from the quoted article will then somewhat apply, but the only devices that get Android updates directly from Google are Google devices (Nexus, Pixel, Android One).
Edit: part of why this is the case, IIRC, has to do with hardware. OEMs, including Google, have to test each build to make sure it works with their specific configurations. The OEMs and carriers then also test it with any preinstalled software. Bugs still get through, mind you, but that’s why there’s this weirdness. That’s also why they drop support, though, since OEMs and carriers have so many devices…
1 user thanked author for this post.
Viewing 10 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
3 hours, 16 minutes ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
1 hour, 14 minutes ago -
Auto Time Zone Adjustment
by
wadeer
7 hours, 45 minutes ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
5 hours, 25 minutes ago -
Manage your browsing experience with Edge
by
Mary Branscombe
48 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
51 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
1 hour, 14 minutes ago -
Apps included with macOS
by
Will Fastie
52 minutes ago -
Xfinity home internet
by
MrJimPhelps
47 minutes ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
45 minutes ago -
Debian 12.11 released
by
Alex5723
1 day, 4 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
1 day, 8 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
12 hours, 1 minute ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
4 hours, 26 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
2 days, 1 hour ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
1 day, 15 hours ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
2 days, 4 hours ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
1 day, 20 hours ago -
Some advice for managing my wireless internet gateway
by
LHiggins
1 day, 3 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
5 hours, 56 minutes ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
2 days, 13 hours ago -
Sometimes I wonder about these bots
by
Susan Bradley
1 hour, 46 minutes ago -
Does windows update component store “self heal”?
by
Mike Cross
2 days ago -
Windows 11 Insider Preview build 27858 released to Canary
by
joep517
3 days, 3 hours ago -
Pwn2Own Berlin 2025: Day One Results
by
Alex5723
1 day, 11 hours ago -
Windows 10 might repeatedly display the BitLocker recovery screen at startup
by
Susan Bradley
1 day ago -
Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview
by
joep517
3 days, 6 hours ago -
Windows 10 Build 19045.5912 (22H2) to Release Preview Channel
by
joep517
3 days, 6 hours ago -
Kevin Beaumont on Microsoft Recall
by
Susan Bradley
58 minutes ago -
The Surface Laptop Studio 2 is no longer being manufactured
by
Alex5723
3 days, 14 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.