TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Service news

Unveiling Encryption Key Vulnerability in Qualcomm-Powered Android Devices

Paul Balo by Paul Balo
July 4, 2016
in Service news
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • An in-depth analysis led by an Israeli researcher, Gal Beniamini, has discovered a worrying vulnerability in Android’s Full Disk Encryption (FDE) on hardware using Qualcomm’s chip.
  • The study, published [in his blog post](https://bits-please.blogspot.com.ng/2016/06/extracting-qualcomms-keymaster-keys.html) casts a spotlight on the unwelcome comparison between the encoder safety of iOS – which was ultimately decimated by...
  • Two vulnerabilities, [CVE-2015-6639](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6639) and [CVE-2016-2431](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2431) form the crux of this research.

An in-depth analysis led by an Israeli researcher, Gal Beniamini, has discovered a worrying vulnerability in Android’s Full Disk Encryption (FDE) on hardware using Qualcomm’s chip. The study, published [in his blog post](https://bits-please.blogspot.com.ng/2016/06/extracting-qualcomms-keymaster-keys.html) casts a spotlight on the unwelcome comparison between the encoder safety of iOS – which was ultimately decimated by the FBI – and Qualcomm boosted Android devices, which maintain encryption keys in the software.

Two vulnerabilities, [CVE-2015-6639](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6639) and [CVE-2016-2431](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2431) form the crux of this research. Although Google and Qualcomm have reportedly fixed them, with the first in January and the latter in May, they still awarded the researcher for his effort under the bug bounty program.

Interestingly, while security team Duo Security confirmed that both flaws have been repaired on a large scale, they estimate that 37% of Android devices that employ the Duo app are still susceptible to attacks because patches have yet to reach them. Furthermore, Beniamini suggested that some Android devices once susceptible but subsequently repaired, including a tested Nexus 6 unit, can be reverted to their insecure former states.

Beniamini’s research imperatively included [exploit code](https://github.com/laginimaineb/ExtractKeyMaster) that extracts the disk encryption keys by effectively leveraging both vulnerabilities in [TrustZone](http://www.arm.com/products/processors/technologies/trustzone/index.php), a suite of security-related features within the [ARM processors](http://www.arm.com/products/processors/index.php) that Qualcomm provides to phone manufacturers.

A measure of the encryption potency of Apple’s iOS devices and Qualcomm augmented Android devices was provided by the researcher. He cited that each appliance has a unique, unchangeable 256-bit key termed the UID, which is arbitrarily generated and integrated into the device’s hardware during manufacturing. Even Apple is unable [to pry out from the device](http://techbooky.com/even-apple-cannot-access-encrypted-data-on-newer-iphones-plus-over-6-5-million-pay-for-apple-music/) once sealed in.

This research starkly highlights the considerable difference between the encryption provided by Apple’s iOS and Qualcomm’s Android devices. It is vital to note that while it might be a complex task to break into these Android devices, it is not entirely impossible with advanced techniques or a potentially robust password.

Beniamini’s research provides the following four concrete takeaways:

Also worth reading
EU Orders Google To Open Android And Search Data To Rival AI Assistants Googlebooks: Google’s Android-Powered AI Laptops Are Coming This Year Android 17 Is Here and Google Wants Gemini to Run Your Entire Phone Google Rolls Out Media App Switcher For Android Auto Google’s AI Studio Can Now Spin Up Native Android Apps in Minutes Critical Vulnerability In Microsoft Authenticator Exposes Users To Token Theft

1. **The key derivation is not hardware bound.** This suggests that the vulnerability is software-based, escalating potential threat levels for millions of devices.

2. **OEMs can comply with law enforcement to break Full Disk Encryption.** Essentially, it would enable law enforcement agencies to effortlessly execute a brute-force attack on the FDE password off the device using leaked keys.

3. **Patching TrustZone vulnerabilities doesn’t necessarily provide full protection.** Attackers could potentially exploit TrustZone to extract keys and use them to brute-force the encryption.

4. **Android FDE is only as secure as the TrustZone kernel or KeyMaster.** This means finding vulnerabilities in either of them could potentially expose the KeyMaster keys, enabling off-device attacks on Android [FDE](https://www.techbooky.com/).

Android operating system vulnerabilities have often been the subject of numerous studies, with varying results. Despite several security breaches, the overarching problem lies not with Android itself, but primarily with third-party devices or applications susceptible to security breaches.

This article was updated in 2025 to reflect modern realities.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • Qualcomm
    Zero-Day Flaw in Qualcomm Chips Exploited to Attack…
  • qualcomm-extends-support-for-updates-on-android-devices-snapdragon-8-elite
    Qualcomm Aims at Expanding Android Phone Support
  • android
    Google Patches 107 Flaws Including 2 Android Zero-Days
  • Chrome-Android-Speedometer-benchmark-1
    Android Device Speedometer Benchmark Scores Are…
  • whatsapp icon
    WhatsApp Fixes Bug in View-Once Media Feature
  • post-hero-vulnerability
    Gogs Fixes Critical Zero-Day Bug That Enabled Remote…
  • 2026-05-08-Linux_LPE-Dirty_Frag-Aufmacher-3f0ce52bb528ed97
    New Linux Zero-Day Flaw 'Dirty Frag' With Root…
  • Win 8
    Qualcomm Tops Estimates with Strong Handset Chip…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Service news
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: androidqualcommsecurity
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Snapchat Brings Spotify Listening To Snap Map With Now Playing July 27, 2026
  • Threads Users Can Now DM Meta AI As The Assistant Moves Deeper Into Social Apps July 27, 2026
  • NVIDIA Launches Open Secure AI Alliance To Make Open Models A Cyber Defence Tool July 27, 2026
  • CXMT Surges 470% As China Bets Big On AI Memory Chips July 27, 2026
  • Africa Launches ATLAS Umoja AI To Build Models For African Languages July 27, 2026
  • SpaceX Deploys V3 Starlink Satellites But Loses Another Super Heavy Booster July 26, 2026
  • The Boring Company Reportedly Seeks $4B As Musk’s Tunnel Bet Gets A $20B Valuation July 26, 2026
  • Claude Opus 5 Gives Anthropic A Cheaper Answer To The Fable 5 Problem July 25, 2026
  • Meta Makes Facebook Verified Free As AI Scams Make Real People Harder To Spot July 24, 2026
  • SAP Cloud Growth Eases Fears That AI Will Weaken Enterprise Software July 24, 2026
  • US Lawmakers Push AI Kill Switch Bill After OpenAI Rogue-Model Incident July 24, 2026
  • Airtel Money’s $61B Quarter Makes Its London IPO A Bigger Africa Fintech Story July 24, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.