Jump to content

Very severe Android 5.0+ lock screen bug found

Master Disaster

Users of Cyanogenmod have reported a bug with Android 5.0, 5.01 & 5.02. Initially it was suspected to be a Cyanogen specific issue but they've confirmed it also exists in the stock images.

Basically certain applications (QQ Browser is the only one listed so far) allow a user to completely bypass the lock screen when it's setup to use a swipe pattern with a very simple button press routine.

The Cyanogen team are advising all Android 5 users to uninstall QQ Browser for now, they expect the patch in the next nightly however that's only for Cyanogenmod users, stock users will have to wait for Google to.patch it.

Source - http://www.androidheadlines.com/2015/03/lock-screen-bug-plaguing-android-5-0-and-later-devices.html

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

wow thats just, wow.

 

thanks obama

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

So its only if you use CM with a specific app? So it wont effect that many people and this title is clickbate. A major bug would be bypassing without any other app imo.

Intel I9-9900k (5Ghz) Asus ROG Maximus XI Formula | Corsair Vengeance 16GB DDR4-4133mhz | ASUS ROG Strix 2080Ti | EVGA Supernova G2 1050w 80+Gold | Samsung 950 Pro M.2 (512GB) + (1TB) | Full EK custom water loop |IN-WIN S-Frame (No. 263/500)

Link to comment
Share on other sites

Link to post
Share on other sites

So its only if you use CM with a specific app? So it wont effect that many people and this title is clickbate. A major bug would be bypassing without any other app imo.

No, it was reported by Cyanogen users but the Cyanogen team have confirmed its present in all android images including the stock one so it effects everyone using Android 5.

The bug report lists QQ Browser and other apps so its not just one app, in fact no one really knows how bad it really is right now though I'm sure there's users trying every possible app to find out.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

I guess I'll stay away from QQ and hope google gets their s**t together.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

It's not a very severe bug by any means. 

It's a small thing they forgot to add in, and the app's developers are also at some fault.

 

Anyway, knock code FTW.

i5 4670k @ 4.2GHz (Coolermaster Hyper 212 Evo); ASrock Z87 EXTREME4; 8GB Kingston HyperX Beast DDR3 RAM @ 2133MHz; Asus DirectCU GTX 560; Super Flower Golden King 550 Platinum PSU;1TB Seagate Barracuda;Corsair 200r case. 

Link to comment
Share on other sites

Link to post
Share on other sites

Only one app?....

Really?

Hardly news.

Link to comment
Share on other sites

Link to post
Share on other sites

Did anyone notice the 4:04 time on the screen? :) Pretty funny in context with the bug. 

Link to comment
Share on other sites

Link to post
Share on other sites

It's not a very severe bug by any means. 

It's a small thing they forgot to add in, and the app's developers are also at some fault.

 

Anyway, knock code FTW.

Sure, the bug is caused by the app developers, but getting past the lock screen on android like that shouldn't be possible with any application. (or else, malicious apps could sick a backdoor in every phone they're installed on)

 

Kind of like saying it's purely a frontend web dev's fault that some php injection can return an arbitrary user's password after a failed login. Sure, that's a terrible bug in the authentication code, but actual passwords shouldn't be anywhere on the server. Ever.

Link to comment
Share on other sites

Link to post
Share on other sites

'very severe'

Link to comment
Share on other sites

Link to post
Share on other sites

So you're telling me some random crap Chinese browser triggers a bug if you have CM and this browser installed at the same time?  That sounds like a horribly debilitating bug that is going to be THE END OF ANDROID!!!! 

 

Seems to me that everyone is trying their damndest to find any flaw whatsoever in Lollipop, and there seems to not be many. First the select few Nexus 5's on a specific provider bug, and now this.  Yes there will be a couple minor, hardly noticeable bugs to 99.9% of user base (I've never even heard of QQ Browser), but come on, this is stretching it a little don't you think?  Especially calling it "Very Severe".  Probably Iphone users.  :rolleyes:

 

These sensationalist, clickbait titles need to stop. 

PC: CPU - FX 8350 @4.5 Ghz | GPU - 3x R9 290 @1100 core/1300 memory | Motherboard - Asus Crosshair V Formula Z | RAM - 16 GB Mushkin Redline 1866 Mhz | PSU - Corsair AX 860w | SSD - ADATA SX900 256 GB | HDD - Seagate 3TB 7200RPM | CPU Cooler - Noctua NH D-14 | Case - Cooler Master HAF Stacker 935

Peripherals: Monitor - ASUS VN248H-P IPS | Keyboard - Corsair K70 | Mouse - Corsair M65 | Headphones - ASUS ROG Orion Pro

Link to comment
Share on other sites

Link to post
Share on other sites

So you're telling me some random crap Chinese browser triggers a bug if you have CM and this browser installed at the same time?  That sounds like a horribly debilitating bug that is going to be THE END OF ANDROID!!!! 

 

Seems to me that everyone is trying their damndest to find any flaw whatsoever in Lollipop, and there seems to not be many. First the select few Nexus 5's on a specific provider bug, and now this.  Yes there will be a couple minor, hardly noticeable bugs to 99.9% of user base (I've never even heard of QQ Browser), but come on, this is stretching it a little don't you think?  Especially calling it "Very Severe".  Probably Iphone users.  :rolleyes:

 

These sensationalist, clickbait titles need to stop. 

 

Well... Getting past the lock screen is a problem. 

I'm guessing the chinese people from china use this browser. China has probably 160 Million active android users. (According to this report https://www.techinasia.com/china-active-android-ios-users-2012/)

I think this is quite big enough of a user base for it to be a known problem. 

i5 2400 | ASUS RTX 4090 TUF OC | Seasonic 1200W Prime Gold | WD Green 120gb | WD Blue 1tb | some ram | a random case

 

Link to comment
Share on other sites

Link to post
Share on other sites

wow thats just, wow.

 

thanks obama

 

Obama Care might be to blame, who knows???

 

 

 

 

 

 

 

No, I'm not serious - I'm not a Fox new anchor (read, retard) 

i5 4670K | ASUS Z87 Gryphon | EVGA GTX 780 Classified | Kingston HyperX black 16GB |  Kingston HyperX 3K 120GB SSD | Seagate Barracude 3TB - RAID 1 | Silverstone Strider Plus 750W 80Plus Silver | CoolerMaster Hyper 212X | Fractal Design Define Mini 
 

Link to comment
Share on other sites

Link to post
Share on other sites

Well... Getting past the lock screen is a problem.

I'm guessing the chinese people from china use this browser. China has probably 160 Million active android users. (According to this report https://www.techinasia.com/china-active-android-ios-users-2012/)

I think this is quite big enough of a user base for it to be a known problem.

160 million android users, but according to the QQ Browser app, only a little more than 1 million have even downloaded it. Cross section that with how many of those people also have cyanogen mod, and subtract the people that don't use the browser app anymore, or have since switched to a non Android phone. I'd say it probably doesn't even affect that many people in the grand scheme of things. And definitely not enough to warrant an immediate update from Google.

PC: CPU - FX 8350 @4.5 Ghz | GPU - 3x R9 290 @1100 core/1300 memory | Motherboard - Asus Crosshair V Formula Z | RAM - 16 GB Mushkin Redline 1866 Mhz | PSU - Corsair AX 860w | SSD - ADATA SX900 256 GB | HDD - Seagate 3TB 7200RPM | CPU Cooler - Noctua NH D-14 | Case - Cooler Master HAF Stacker 935

Peripherals: Monitor - ASUS VN248H-P IPS | Keyboard - Corsair K70 | Mouse - Corsair M65 | Headphones - ASUS ROG Orion Pro

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×