Even one click on the link is able to run a chain of operation of vulnerabilities, which overcomes several levels of smartphone protection at once. Nebula Security introduced IonStack is a test exploit for Android 17 that combines two previously unknown vulnerabilities and allows you to gain full control over the device without additional actions on the part of the owner.
The attack starts with a malicious page in Firefox. Error in browser versions up to 151.0.2 allows you to execute the code within the process that processes the content of the site. IonStack then uses a second vulnerability in the Linux kernel underlying Android and goes beyond the browser’s isolated environment.
Access to the Linux kernel opens up the widest possible possibilities. In the demonstration, the chain allows you to extract data, monitor the actions of the owner, install a hidden access channel and remotely control the smartphone. Nebula Security calls the development of the first public demonstration of obtaining root access on Android 17 with one click.
Both errors were detected by an automated VEGA code analyzer. According to the company, the vulnerability used in the Linux kernel was present in the code for about 15 years and went unnoticed in previous inspections. Such chains are especially dangerous, because they associate the error in the browser with the capture of the operating system and bypass several protective barriers.
Nebula Security has already transmitted information to the developers and found no signs of real attacks. IonStack remains a demonstration, not a confirmed tool of intruders.
To reduce the risk, you should upgrade Firefox to version 151.0.2 or newer. After posting a fix for the Linux kernel, an appropriate system update should be installed. Organizations are also encouraged to update browsers and kernels on enterprise devices faster.
The attack starts with a malicious page in Firefox. Error in browser versions up to 151.0.2 allows you to execute the code within the process that processes the content of the site. IonStack then uses a second vulnerability in the Linux kernel underlying Android and goes beyond the browser’s isolated environment.
Access to the Linux kernel opens up the widest possible possibilities. In the demonstration, the chain allows you to extract data, monitor the actions of the owner, install a hidden access channel and remotely control the smartphone. Nebula Security calls the development of the first public demonstration of obtaining root access on Android 17 with one click.
Both errors were detected by an automated VEGA code analyzer. According to the company, the vulnerability used in the Linux kernel was present in the code for about 15 years and went unnoticed in previous inspections. Such chains are especially dangerous, because they associate the error in the browser with the capture of the operating system and bypass several protective barriers.
Nebula Security has already transmitted information to the developers and found no signs of real attacks. IonStack remains a demonstration, not a confirmed tool of intruders.
To reduce the risk, you should upgrade Firefox to version 151.0.2 or newer. After posting a fix for the Linux kernel, an appropriate system update should be installed. Organizations are also encouraged to update browsers and kernels on enterprise devices faster.