Nearly all Android phones at risk of attack — what to do

Android malware
(Image credit: Shuterstock)

A major security flaw affecting nearly every Android smartphone has been discovered, which could potentially allow hackers to remotely access and control a smartphone's camera and microphone. 

The flaw, discovered by Check Point Research, found a vulnerability in the audio decoders of Qualcomm and MediaTek chips; an unprivileged Android app could then use this security hole to change its privileges, then access a user's camera and microphone and eavesdrop on their communications. 

Check Point Research revealed the vulnerability today (April 22), but had previously disclosed the issue to MediaTek and Qualcomm, which patched their firmware in December 2021.

Nearly all Android phones affected

Together, Qualcomm and MediaTek's chips power nearly 95 percent of all Android smartphones in the U.S., according to IDC

This particular exploit involves the Apple Lossless Audio Codec (ALAC), which was launched in 2004. While Apple has updated its proprietary version of the decoder, the shared code has not been patched since 2011, according the Check Point Research. It was this code that Qualcomm and MediaTek used for their audio decoders. 

Prior to releasing a firmware update, if an attacker were to implant an audio file with malicious code onto a vulnerable Android smartphone, they could then access the camera and microphone. 

What you can do

As always, to make sure your device is protected, check to see that its firmware and operating system are fully updated, and that you have installed any security patches. You should also avoid downloading or installing any apps or files from untrusted sources or unofficial app marketplaces. For an additional layer of security, you can also install one of the best android antivirus apps

TOPICS
Mike Prospero
U.S. Editor-in-Chief, Tom's Guide

Michael A. Prospero is the U.S. Editor-in-Chief for Tom’s Guide. He oversees all evergreen content and oversees the Homes, Smart Home, and Fitness/Wearables categories for the site. In his spare time, he also tests out the latest drones, electric scooters, and smart home gadgets, such as video doorbells. Before his tenure at Tom's Guide, he was the Reviews Editor for Laptop Magazine, a reporter at Fast Company, the Times of Trenton, and, many eons back, an intern at George magazine. He received his undergraduate degree from Boston College, where he worked on the campus newspaper The Heights, and then attended the Columbia University school of Journalism. When he’s not testing out the latest running watch, electric scooter, or skiing or training for a marathon, he’s probably using the latest sous vide machine, smoker, or pizza oven, to the delight — or chagrin — of his family.

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
Cars on the road with blue overlay indicating what data may be contained about the drivers within
Millions at risk due to severe security flaw in license plate readers
Find My iPhone
Apple Find My hack turns any Bluetooth device into a secret AirTag — what we know
Latest in Android Phones
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
vivo x200 ultra camera array
Vivo’s next premium phone could have a camera unlike anything we’ve seen before — here’s how
Latest in News
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Apple iPhone 16 & 16 Plus hands-on.
iPhone 17 just tipped for this long overdue Pro feature in new report
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Max Rockatansky (Tom Hardy) stands on the hood of a car with an explosion behind him in a promotional still for Warner Bros. "Mad Max:Fury Road"
One of the best action movies ever made is leaving Netflix very soon — here's your last day to stream 'Mad Max: Fury Road'
nvidia rtx 50 series
RTX 5060 Ti release date just tipped for April 16 — HP seemingly confirms Nvidia's next-gen GPUs
Ray-Ban Meta Smart Glasses
Samsung’s 'Haean' smart glasses will reportedly launch this year — here's everything to expect