• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Ring patched an Android bug that could have exposed video footage

August 18, 2022
Share on FacebookShare on Twitter

Enlarge / Ring camera images give you a view of what’s happening and, in one security firm’s experiments, a good base for machine learning surveillance.

Ring

Amazon quietly but quickly patched a vulnerability in its Ring app that could have exposed users’ camera recordings and other data, according to security firm Checkmarx.

Checkmarx researchers write in a blog post that Ring’s Android app, downloaded more than 10 million times, made an activity available to all other applications on Android devices. Ring’s com.ring.nh.deeplink.DeepLinkActivity would execute any web content given to it, so long as the address included the text /better-neighborhoods/.

That alone would not have granted access to Ring data, but Checkmarx was able to use a cross-site scripting vulnerability in Ring’s internal browser to point it at an authorization token. Next, Checkmarx obtained a session cookie by authorizing that token and its hardware identifier at a Ring endpoint and then used Ring’s APIs to extract names, email addresses, phone numbers, Ring device data (including geolocation), and saved recordings.

Checkmarx’s video, featuring footage tests and a hoodie-wearing hacker.

And then Checkmarx kept going. With access to its own example users’ recordings and any number of machine-learning-powered computer vision services (including Amazon’s own Rekognition), the security firm went wide-angle. You could, the firm found in its tests, scan for:

Advertisement

  • Safes, and potentially their combinations
  • Images of documents containing the words “Top Secret” or “Private”
  • Known celebrities and political figures
  • Passwords and passcodes
  • Children, alone, in view of a Ring camera

To be clear, the vulnerability was seemingly never exploited in the wild. Checkmarx reported it on May 1, Amazon confirmed its receipt the same day, and a fix was released (3.51.0 for Android, 5.51.0 for iOS). Checkmarx says that Amazon responded to the high-severity issue with acknowledgment but also deferral. “This issue would be extremely difficult for anyone to exploit because it requires an unlikely and complex set of circumstances to execute,” Amazon told Checkmarx.

Erez Yalon, VP of security research at Checkmarx, told The Record that taped-together vulnerabilities are coveted among hackers.

“Each would be problematic, but chaining them together, something hackers always try to do, made it so impactful.”

(Update 1:50 p.m. ET: Updated to correct spelling of Erez Yalon’s name. Ars regrets the error.)

Next Post

Cameo now lets you have 10-minute calls with celebs – TechCrunch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • IRONSCALES brings AI email agents & threat intelligence to RSAC
  • Zayo provides critical connectivity infrastructure for AI, cloud datacentres  
  • Review: Screamer (PS5) – Finally, a Racing Game Doing Something Interesting – Push Square
  • The 9 best beauty deals live ahead of Amazon’s Big Spring Sale
  • Google Contacts preps a smarter new look for contact profiles

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously