3 ms·
There's no remote exploit though, right? So the only way an attacker could turn this into a botnet would be to somehow get Android apps to run attacker controll
by workthrowaway27 9y ago
There's no remote exploit though, right? So the only way an attacker could turn this into a botnet would be to somehow get Android apps to run attacker controlled code or exploit existing code that fits the pattern described in the attacks (seems not to exist in practice). These aren't super high bars, but they do make the exploit significantly harder.
- jimmaswell 9y agoCouldn't old Android web browsers be targeted?
- workthrowaway27 9y agoIt seems like it (didn't see that there was a JS version of the exploit until after I posted), although they can only read from the address space of the process the JS code is running in. I think tabs get individual processes (in Chrome at least), not sure about Firefox or other browsers, so I'm not sure how bad this is in practice.