article-header

Product

Security Update: APEX Modules Vulnerability FIXED

Product

In November 2023, a security vulnerability was detected in an assorted list of smartphones, including the Fairphone 5, by Meta Red Team X. Fairphone took immediate action to release a security fix in mid-December that solved the issue, meaning that every Fairphone model is now secured against this vulnerability.

The vulnerability detected by Meta Red Team X affects APEX modules and the way they are signed; APEX modules allow original equipment manufacturers (“OEMs”) to update specific portions of the system without issuing a full over-the-air (OTA)  update, but instead only delivering the subsystems that need to be updated. These modules need to be signed with the private key of the OEM during the build process, but it was found that our building process had a shortcoming, and we were using a test key (present in the Android source code build tree) instead of Fairphone’s private key.

This means that, in practice, it would have been possible for an attacker to substitute the incorrectly signed modules with other files signed with the same test key, potentially containing malicious code. Having said that, this is not easy to exploit. The substitution would require either physical access to the device, along with the debugging options activated, or remote access obtained through a chain of other critical vulnerabilities. Yet, it did present a high severity vulnerability.

Triggered by the report on Fairphone 5, we also opened an internal investigation on Fairphone 4 and Fairphone 3/3+, where we found similarly affected APEX modules. The vulnerability was resolved in December 2023 for all Fairphone devices with the following software versions, respectively:

  • Fairphone 5: TT3Y.A.127 (released on the 11th of December 2023)
  • Fairphone 4: TP20.C.087 (released on the 25th of December 2023)
  • Fairphone 3/3+: 6.A.023.1 (released on the 25th of December 2023)

If you have not updated your phone recently, we invite you to install the most recent software version available to you. You can always check manually for system updates in the Settings menu under the System sub-menu. More information on the vulnerability can be found on the original report or the security advisory published by Red Team X.

Share this post

Related beiträge See all posts

  • Zero Exposure: This is how we make factories fairer

    Zero Exposure: This is how we make factories fairer

    It’s funny when you think about it. In the 1940s, cigarette companies would actively use doctors in their advertising campaigns, leading to such classics as ‘More doctors smoke Camels’. If you went by the ads, cigarettes were physician-tested and approved. Of course, today, these things won’t fly anymore, thanks to strict regulations in place to...

    Mehr Lesestoff
  • 14 Reasons Why You’ll Love Fairphone’s Audio Range

    14 Reasons Why You’ll Love Fairphone’s Audio Range

    For those of you who don’t know this already, Fairphone doesn’t just make smartphones. It was in 2021 that we took our first steps into the world of sustainable audio, releasing the Fairphone TWS earbuds. And while they boasted a longer battery life than the competition and used Fairtrade gold in the supply chain, they...

    Mehr Lesestoff

Fairphone Newsletter

Du brauchst kein neues Smartphone, aber willst immer informiert sein?

Abonniere unseren Newsletter, um regelmäßig über alle Neuigkeiten rund um Fairphone

Melde dich für den Newsletter an und erhalte 5€ Discount auf deine nächste Bestellung.

Dein Rabatt von 5€ wird an die von dir angegebene E-Mail-Adresse gesendet. Der Gutschein kann bei deiner nächsten Bestellung über 75 € eingelöst werden. Bitte beachte, dass unsere Kommunikationssprache Englisch ist. Wir bitten dich um deinen Namen und deine E-Mail-Adresse, damit du unseren Newsletter für tolle Projekt-Updates erhalten kannst. Du kannst deine Einwilligung jederzeit widerrufen. Wir verwenden MailChimp als E-Mail-Plattform. Indem du auf „Abonnieren“ klickst, erkennst du an, dass die von dir angegebenen Informationen an MailChimp zur Verarbeitung in Übereinstimmung mit deren Datenschutzrichtlinien und Geschäftsbedingungen übertragen werden.

Close