The 5G mobile phone has not been used yet, the loophole of the chip came out first

The complexity of the chip determines that loopholes cannot be "cured".
If we say that the global core shortage continues, it spreads from auto companies and mobile phone manufacturers to the home appliance industry, hitting the production progress of corporate products, increasing production costs, and indirectly affecting consumers. Then, the problem of chip security vulnerabilities will directly cause a serious impact on users' various privacy and data.
After Qualcomm's chip delivery was delayed for 7 months due to capacity problems, a new round of crisis has emerged.
After the May Day holiday, Check Point Research, an overseas security company, discovered a vulnerability in Qualcomm’s modem (MSM) chip. The modem chip is mainly responsible for mobile phone communication. It has 2G, 3G, 4G, and 5G functions on a system-on-chip (a single chip integrates a complete system).
In other words, users need a modem chip to send text messages, make calls, and surf the Internet with their mobile phones. Once the modem chip has vulnerabilities, hackers or network attackers can use these vulnerabilities to attack through the Android phone system and inject malicious and invisible code. .
When targeted by hackers, the user’s text messages, call records, call information, and even unlock the user identification module on the mobile device, store the user’s network identity verification information and contact information.
It is reported that online public data shows that about 40% of mobile phones in the global market use Qualcomm chips. These mobile phone manufacturers include mobile phone brands such as Google, Samsung, Xiaomi, OPPO, vivo, and OnePlus. This means that nearly half of the world's mobile phone users may face privacy leaks, mobile phones being monitored and frozen remotely, and the risk of data loss.
What is going on with the vulnerability of the mobile phone chip? Can the risk be easily solved as long as the software patch is used to fix it? The leak may not be so optimistic, and it may be impossible to resolve it at all.

Full of loopholes
This is not the first time Qualcomm has chip bugs.
In 2020, a study at the DEFCON Global Hacking Conference showed that there are six serious vulnerabilities in Qualcomm's mobile chips that will affect tens of thousands of Android smartphones and tablets. Cybersecurity researchers also found that the vulnerability is mainly Qualcomm’s DSP chip (digital signal processor). The DSP is responsible for converting services such as voice, video, GPS location sensors into computable data, and controls the user’s Android system and Qualcomm processor. Real-time request processing between hardware.
https://pingdirapp31.directoryup.com/fairfax/top-level-category/next-day-garage-door-services
http://www.ethioffer.com/fairfax/top-level-category/next-day-garage-door-services
https://www.directory2020.com/rocksville/building-material/next-day-garage-door-services
http://www.u2freeclassifiedads.com/455/posts/63/2162/282306.html
If the DSP is flawed, hackers can collect and access user photos, videos, call records, real-time microphone data, GPS location information, and so on.
Imagine that the information about the location where a user goes out, as well as the photos, videos, and even the content of conversations with others through the microphone can be understood by remote hackers and network attackers. In severe cases, the hacker may damage the target mobile phone, remotely turn on the user's microphone, implant malicious software that the mobile phone cannot detect at all, initiate a denial of service attack, freeze the mobile phone, and use the data on the mobile phone at will.
It is worth noting that there are more than 400 vulnerable codes on Qualcomm DSP chips. As long as manufacturers and users do not have any intervention measures, mobile phones may become "spy tools."
But the last time is different from 2020, Qualcomm's loopholes appeared in the modem chip.
As mentioned earlier, the modem is responsible for the communication function of the mobile phone. For example, the mobile phones on the market are gradually upgraded to 5G mobile phones. The 5G performance and signal reception functions of the mobile phone depend largely on the performance of the modem chip.
Like the DSP chip vulnerability, hackers implant malicious code into the modem chip through the Android system, and cybercriminals can easily explore the latest 5G code from the manufacturer. The position of the chip where the code is injected is different, and the function affected is different.
For example, modem chips mainly focus on mobile phone call functions, access user call history, monitor user conversations, unlock mobile phone SIM cards, and go beyond the control of telecom operators.
In any case, these chip vulnerabilities will have a great impact on user privacy data security and property security. Some people say that chip companies can completely prevent these vulnerabilities from being exploited by criminals on the network by issuing vulnerability patches, but in fact, it is not easy to implement.
Problem or no solution
After the chip vulnerabilities were announced by a third-party organization, Qualcomm refused to make a statement. Instead, it issued a statement stating that Qualcomm is verifying the problem and providing appropriate buffer measures for OEM manufacturers. There is currently no evidence that these vulnerabilities are being exploited. Of course, Qualcomm Encourage users to update device patches.
Qualcomm's statement disguisedly acknowledged the existence of these high-risk loopholes. In fact, Qualcomm noticed the DSP chip vulnerability in 2020 long before the third-party attack agency discovered it. In July of the same year, it developed a patch for cracking certain WPA2 encrypted wireless networks. Patches for these vulnerabilities.
But even if Qualcomm released a patch, the effect will not be satisfactory.
To quote Yaniv Balmas, head of research at Check Point, "These chip vulnerabilities have caused hundreds of millions of mobile phones around the world to run naked. Repairing these phones is an impossible task."
On the one hand, these patches are mainly for users who upgrade to the new Android system, and users of old Android versions are not protected. Stat Counter data shows that about 19% of the world's Android phones run the Android Pie 9.0 operating system released by Google in August 2018, and over 9% of users' phones run the Android 8.1 Oreo operating system released by Google in December 2017. Quite a few Android phone users are older versions.
On the other hand, Qualcomm is only one link in the entire chip security crisis event chain, and it also needs the cooperation of OEM manufacturers, namely mobile phone manufacturers, and Google. Qualcomm needs to fix vulnerabilities in the chips and operating hardware first, and then deliver them to mobile phone manufacturers, or hand over the fixes to mobile phone manufacturers.
It is not enough for Qualcomm to complete the bug fixes. How mobile phone manufacturers ensure that the patches are integrated into mobile phones that are being assembled or circulating on the market is of great uncertainty. As we all know, mobile phone manufacturers are slow to update their systems. For example, after Google released a stable version of Android 10 in 2019, it will take at least one year for most users to transition to the new mobile phone system. If the mobile phone version is too low or the service policy is different, some mobile phones cannot even update the latest system. Although Google is a mobile phone system developer, it cannot directly update the latest systems and patches for mobile phone users.
https://pingdirapp31.directoryup.com/rocksville/top-level-category/garage-door-repair-maryland
http://www.ethioffer.com/rocksville/top-level-category/garage-door-repair-maryland
https://www.directory2020.com/rocksville/building-material/garage-door-repair-maryland
http://pingdirapp19.directoryup.com/fairfax/sample-category/garage-door-repair-maryland
http://www.regtechdirectory.com/fairfax/consultants/garage-door-repair-maryland
https://www.yellowpagesb.com/fairfax/construction/garage-door-repair-maryland
http://www.greenvillecityguide.com/fairfax/home-services/garage-door-repair-maryland
https://www.fixerhub.com/fairfax/home-services/garage-door-repair-maryland
https://pingdirapp28.directoryup.com/fairfax/sample-category/garage-door-repair-maryland
http://www.myprideglobal.com/fairfax/home-services/garage-door-repair-maryland
https://www.dennisdemo.com/fairfax/home-services/garage-door-repair-maryland
https://www.onmap.ae/fairfax/business-services/garage-door-repair-maryland
https://helpsellmyfsbo.com/fairfax/garage-door-repair-maryland
https://www.cityyap.com/fairfax/local-home-services/garage-door-repair-maryland
https://www.localpines.com/construction-companies/garage-door-repair-maryland
https://www.smartfindonline.com/us/home-renovations-and-maintenance/garage-door-repair-maryland
https://www.1800womsga.com/fairfax/local-business-1/garage-door-repair-maryland
https://www.lodgingowners.com/fairfax/campgrounds/garage-door-repair-maryland
http://www.justicesquared.com/fairfax/social-security/garage-door-repair-maryland
https://www.mentorhub.info/sponsors/garage-door-repair-maryland
https://www.ram.directory/fairfax/home-services/garage-door-repair-maryland
http://www.aidfortheneedy.org/fairfax/sample-category/garage-door-repair-maryland
http://www.csafind.com/fairfax/sample-category/garage-door-repair-maryland
https://www.1stopstartup.com/fairfax/home-improvements-service/garage-door-repair-maryland
https://www.preferredprofessionals.com/fairfax/home-services/garage-door-repair-maryland
https://startups.snapmunk.com/fairfax/computer-networking/garage-door-repair-maryland
https://www.dentalbusinessdirectory.com/fairfax/other/garage-door-repair-maryland
http://www.fanshelf.com/fairfax/agent/garage-door-repair-maryland
https://www.cleansway.com/fairfax/business/garage-door-repair-maryland
https://www.homerefinisher.com/fairfax/refinishing/garage-door-repair-maryland
https://www.consultsdirect.com/fairfax/consultant/garage-door-repair-maryland
http://www.findstuff-guam.com/fairfax/professional-services/garage-door-repair-maryland
https://www.counselingnearme.com/fairfax/online-counseling/garage-door-repair-maryland
https://www.referralsoverbreakfast.com/fairfax/home-services/garage-door-repair-maryland
http://www.swizzness.com/fairfax/home-services/garage-door-repair-maryland
https://www.adlocalpages.com/fairfax/home-improvement/garage-door-repair-maryland
http://www.schuckbook.com/fairfax/home-improvement-and-repairs/garage-door-repair-maryland
http://www.fluteplayersdirectory.com/fairfax/business/garage-door-repair-maryland
http://www.proslist.net/fairfax/construction/garage-door-repair-maryland
http://www.naturopathdirectory.com/sample-category/garage-door-repair-maryland
https://www.rightlawyer.com/fairfax/business/alex-haney
http://www.koreaninside.com/fairfax/sample-category/garage-door-repair-maryland
https://www.localhomestaging.com/fairfax/interior-decorators/garage-door-repair-maryland
https://www.gunspace.net/fairfax/garage-door-repair-maryland
http://www.hertstrades.com/fairfax/builders/garage-door-repair-maryland
http://www.mortgagebroker.biz/fairfax/sample-category/garage-door-repair-maryland
https://www.buffalosbest.com/fairfax/home-repair/garage-door-repair-maryland
https://www.communitiesuniting.org/fairfax/volunteer/garage-door-repair-maryland
https://www.buildhq.co.nz/home-renovation/garage-door-repair-maryland
https://www.goodnewspress.us/fairfax/home-garden/garage-door-repair-maryland
More importantly, the complexity of the chip determines that loopholes cannot be "cured".
Take DSP chips as an example. DSP chips are like the "black box" of mobile phones. It is difficult for other people except chip manufacturers to detect how it works, and it is difficult for security workers to test them. Therefore, there are likely to be many mature and unknown security vulnerabilities on the DSP chip.
At the same time, DSP chips carry many innovative functions of modern mobile phones, including mobile phone fast charging and multimedia functions, which are extremely easy to be targeted by hackers. Taking a step back, even if the user upgrades the phone, fixing the vulnerability will not solve the problem.
In 2021, Qualcomm’s chip vulnerabilities appeared on the modem chip. Compared with DSP, the complexity of the modem is even worse. It has thousands of lines of code. There is reason to believe that the old code two or three years ago will have the current new one. In the chip model, hackers can use the old code as a breakthrough point to attack and steal cell phone information.
https://expertgaragedoorrepair.blogspot.com/2021/04/know-everything-about-garage-door.html
https://sites.google.com/view/garagedoorrepairashburn/home?authuser=6
https://garageexpert.tumblr.com/post/647973086166155264/garage-door-repair-in-washington-dc
https://site-4365753-5964-7249.mystrikingly.com/blog/quality-garage-work-in-ashburn-virginia
https://60715b945c63f.site123.me/blog/eco-friendly-garage-doors
https://garagerepair.over-blog.com/2021/04/garage-door-repair-in-ashburn-virginia.html
https://list.ly/list/5XsA-smart-garage-guide
https://www.homify.co.uk/ideabooks/7891763/fixing-your-leaky-garages
https://zenwriting.net/henryjoe/the-advantages-of-new-garage-door-installation-b90t
http://vedadate.com/member/blog_post_view.php?postId=114150
https://cliqafriq.com/read-blog/22066
https://politichatter.com/read-blog/17174
https://ello.co/haneyalex/post/13plk4tou5wwjfbfplheja
https://www.launchora.com/story/why-should-you-call-in-a-garage-door-repair-specia
https://www.onfeetnation.com/profiles/blogs/how-ro-repair-roll-up-garage-doors-1
https://dailygram.com/index.php/blog/884499/what-to-do-with-damage-garage-door/
https://www.bloglovin.com/@haneyalex/fall-checklist-for-garage-door
https://padlet.com/haneyalex59/gf3x58wkfdo8q7u/wish/1427854193
https://teletype.in/@haneyalex/commongarageproblems
https://www.diigo.com/item/note/866hm/xipk?k=2f7b8206e29e680afd9222e4be91c062
https://pharmahub.org/members/9213/blog/2021/04/how-to-choose-the-best-garage-door
https://penzu.com/public/e4a035e0
https://hoomet.com/forums/topic/20453/cost-of-replacing-your-garage-door/view/post_id/29096
https://b3.zcubes.com/v.aspx?mid=7067663&title=how-much-does-a-garage-door-repair-cost-in-alexandria
https://maninisbynehathackeray.blogspot.com/2016/08/the-sarpech-and-kalgi.html
https://www.cbtinterpretations.com/blog/2012/01/24/Thoughts.aspx
https://www.chicagochairrentalcollection.com/blog/2014/07/08/Mr-Mrs.aspx
https://envaya.org/VIATAT/topic/123529
https://storeya.zendesk.com/hc/en-us/articles/221190467?page=1#comment_360002677959
https://hairstylefromcoiging.blogspot.com/2011/08/taditional-lakshmi-pendant-temple.html
https://www.ab9.site/2019/11/bounty-gold-stablecoin.html
https://divisionnihil.blogspot.com/2011/06/shared-fantasy-women-in-gaming.html
https://your-fragrance.com/pl/smartblog/5_witamy-ponownie.html
https://keehuachee.blogspot.com/2016/05/sothebys-to-auction-jaw-dropping-gems.html
https://121newsonlines.blogspot.com/2014/02/actress-tv-producer-deepti-bhatnagar.html
https://enfantsterriblesmagazine.blogspot.com/2014/02/etm-ciff-kids-fall-winter-2014-15.html
https://ruralstops.blogspot.com/2012/07/antique-jewelery-invaluable-joy-of.html
https://4evercarolscreations.blogspot.com/2015/06/haunted-design-house-guest-designer.html
https://streetsmart-india.blogspot.com/2010/08/travel-diary-gem-palace.html
https://youehdn.blogspot.com/2013/07/stunning-art-deco-inspired-bridal.html
https://booksbythewillowtree.blogspot.com/2011/03/vintage-jewelry-design-classics-to.html
https://servicecentercontact.blogspot.com/2015/02/gitanjali-jewellery-stores-help-line.html
https://community.fxhome.com/activity/feed/p9
https://cliqafriq.com/alexhaney
https://politichatter.com/alexxhaney
https://www.directorylib.com/en/domain/nextdaygaragedoorservices.com
http://live.24hourbusinesscamp.com/2009/01/ticketzse-search-engine-for-tickets.html
https://naturaily.23video.com/video/11487434
https://www.accentuatingservice.com/blog/2019/08/19/Blog-Posts-from-81819-On.aspx
https://www.blogohblog.com/dont-let-google-adsense-ban-you/#comment-3664445
http://forum.matrox.com/rtx100/viewtopic.php?p=699385#699385
https://www.exchangecore.com/blog/how-redirect-using-php
https://www.intothegamenexus.com/forum/card-games/transformers-tcg-play-mats-f2p
https://www.vwinc.org/forum/autism-awareness-month/what-is-autism
https://www.beropticmall.com/smartblog/1_creative_design.html
http://traditionsmed.com/fouta/fr/module/smartblog/details?id_post=4
https://www.aquariusartventures.net/blog/2018/09/20/September-2018AquariusArtVenturesnet.aspx
https://www.poslouchej.net/forum/viewtopic.php?p=63903#63903
http://demo8.cmsmart.net/m2_extensions_20/default/blog/off-on-top-10-magento-products
https://www.clarkcountyeducators.org/index.php/blog/299-las-vegas-teacher-fed-up-with-union
http://pumastorejava.co.id/smartblog/34_RISE-UP-WITH-PUMA-AND-CARA-DELEVINGNE.html
https://domani-equestrian.com/en/module/smartblog/details?id_post=3_a_beautiful_creative
https://www.cbtinterpretations.com/blog/2012/01/24/Thoughts.aspx
https://www.americangirldollnews.com/forum/truly-me/do-one-like-this
https://www.polishedandpretty.com/blog/2011/01/13/What-Makeup-Tips-are-YOU-Looking-For-.aspx
http://joyeriabeige.com/smartblog/7_ESTRENAMOS-BLOG-----.html
http://crzykidz.com/smartblog/19_CRZY-KIDZ.html
https://webmail.fugu-mango.com/index.php/blog/le-pop-du-label-paris
https://www.pitterpatterselc.com/blog/2014/01/28/Under-Construction.aspx
https://www.goldensplumbing.com/blog/2016/02/23/Why-we-believe-in-Small-Business-Owners-.aspx
https://www.tmuts.com/board/board_topic/5426374/1001887.htm?page=1
https://www.elschaddeioutreachministriesinc.com/blog/2012/01/10/Community-Outreach.aspx
https://www.chien-de-luxe.com/smartblog/26_Sac-de-Transport-pour-chien---Voyager-en-tout.html
https://www.helloneighborgame.com/forum/troubleshooting/it-wont-work
https://www.lhomeky.org/resources/self-help-forum/looking-to-buy-a-mattress/p-2
https://www.keiteq.org/forum/mold-design-forum/accounting-assignment-help
https://www.raasallstars.com/forum/rfl/rfl-scorboard-update-2-25-20
https://www.triadfs.org/triad-family-services-blog/posts/weighing-the-costs-of-adoption
https://www.esspa.us/board/board_topic/8119411/5502227.htm?page=2
https://www.edirecthost.com/main/message_board?msgbrd=9&topic=7604
https://todometalesjg.com/blog/8_almacenaje-al-estilo-industrial.html
https://www.raasallstars.com/forum/__rfl/rfl-scorboard-update-2-25-20
https://www.nzmedals.com/blog/2013/07/02/update.aspx
https://bugwolf.com/blog/forrester-predicts-greater-digital-focus-for-cios-in-2019
https://ratedrecruitment.co.uk/blog/five-reasons-candidates-choose-to-work-in-the-aviation-industry
https://pumastore.co.id/smartblog/29_Puma-Weave-Xt.html
http://www.young-theatre.com/forums/discussion/miscellaneous/buy-essay-online-from-writing-master
https://www.meryancor.com/en/blog/26_Array%C3%A1n-the-subtle-of-beauty.html
https://kumite-shop.com/index.php?fc=module&module=smartblog&id_post=14&controller=details
http://www.americanrecreational.com/gallery/emodule/477/eitem/491
https://live.shootsta.com/how-to-create-professional-videos-2
https://www.janleehypnosis.com/blog/2011/09/27/Your-Brain.aspx
http://known.bradkozlek.com/2014/user-experience-design-and-desiging-learning-experiences
https://www.narman.ro/en/blog/7_Pantofii-din-piele-Narman
https://incienso-deprimera.com/smartblog/8_fragancias-inciensos.html
http://www.jetzt-fragen.de/seo-selber-machen-oder-doch-agentur-beauftragen.html
https://www.foxhollowfamilyfarm.com/forum/easter-tickets/aethngb-l-nailn-ufabet
https://www.jjminsurance.com/forum/shopping-current-deals/closing-down-sale-at-curvaxe
https://yaguejoyeros.es/index.php?fc=module&module=smartblog&id_post=3&controller=details&id_lang=4
https://envaya.org/tuamke/topic/126787
https://wieszakshop.pl/smartblog/20/tommy-hilfiger-moda.html
https://riotseeds.nl/forum/topic/educcation/?part=3#postid-1137
https://www.pizzeriepiccolo.cz/smartblog/1/lorem-ipsum-dolor-sit-amet.html
https://www.mambriniprotools.com/it/Mambriniprofestoolblog/7_Festool-ti-d%C3%A0-la-carica.html
https://www.sitelike.org/similar/nextdaygaragedoorservices.com/
https://reevesstrategygroup.com/seven-easy-tips-on-seo-for-content-marketing/#comment-74034
https://knowyourmeme.com/users/kevin-son
https://www.instructables.com/member/kevinson021
https://www.huntingnet.com/forum/members/kevinson021.html
https://disqus.com/by/kevinson021/
http://www.cruzroja.es/creforumvolint_en/user/edit/128503.page
http://www.webestools.com/profile-302544.html
https://trello.com/kevinson6/activity
https://slashdot.org/submission/13083310/httpsnextdaygaragedoorservicescom
https://www.eliteservicesnetwork.com/fairfax/industrial/next-day-garage-door-services
https://www.merchantcircle.com/next-day-garage-door-services-fairfax-va
http://www.1pgd.de.rs/blog/post/start-der-neuen-onlinepraesenz-8757
https://www.coast-bookmarks.win/garage-door-repair-washington-dc
https://blog.heidimerrick.com/feature-lady-gun-mag/
http://infohemp.com/news/the-government-does-not-want-to-study-pot/#comment-154182
https://www.mambriniprotools.com/it/Mambriniprofestoolblog/7_Festool-ti-d%C3%A0-la-carica.html
http://vote.sparklit.com/comments.spark?contentID=1161530&pollID=1114423
https://www.greencarpetcleaningprescott.com/board/board_topic/7203902/4079313.htm?page=1
In view of the fact that solving chip vulnerabilities is becoming more and more like an impossible task, as a user, either change to the mobile phone operating system and chip from the Apple mobile phone camp developed by itself and the ecosystem is relatively closed, or beware of all applications from unknown sources Download and install. To a certain extent, Android mobile phone manufacturers, including chip manufacturers, mobile phone manufacturers, and operating system manufacturers should regard user data security as the first priority, and jointly find a security solution that can balance the interests of all parties.
This comment has been removed by the author.
ReplyDeleteThis comment has been removed by the author.
ReplyDelete