article-header

Product

Security Update: APEX Modules Vulnerability FIXED

Product

In November 2023, a security vulnerability was detected in an assorted list of smartphones, including the Fairphone 5, by Meta Red Team X. Fairphone took immediate action to release a security fix in mid-December that solved the issue, meaning that every Fairphone model is now secured against this vulnerability.

The vulnerability detected by Meta Red Team X affects APEX modules and the way they are signed; APEX modules allow original equipment manufacturers (“OEMs”) to update specific portions of the system without issuing a full over-the-air (OTA)  update, but instead only delivering the subsystems that need to be updated. These modules need to be signed with the private key of the OEM during the build process, but it was found that our building process had a shortcoming, and we were using a test key (present in the Android source code build tree) instead of Fairphone’s private key.

This means that, in practice, it would have been possible for an attacker to substitute the incorrectly signed modules with other files signed with the same test key, potentially containing malicious code. Having said that, this is not easy to exploit. The substitution would require either physical access to the device, along with the debugging options activated, or remote access obtained through a chain of other critical vulnerabilities. Yet, it did present a high severity vulnerability.

Triggered by the report on Fairphone 5, we also opened an internal investigation on Fairphone 4 and Fairphone 3/3+, where we found similarly affected APEX modules. The vulnerability was resolved in December 2023 for all Fairphone devices with the following software versions, respectively:

  • Fairphone 5: TT3Y.A.127 (released on the 11th of December 2023)
  • Fairphone 4: TP20.C.087 (released on the 25th of December 2023)
  • Fairphone 3/3+: 6.A.023.1 (released on the 25th of December 2023)

If you have not updated your phone recently, we invite you to install the most recent software version available to you. You can always check manually for system updates in the Settings menu under the System sub-menu. More information on the vulnerability can be found on the original report or the security advisory published by Red Team X.

Share this post

Related articles See all posts

  • How to design a Fairphone 101

    How to design a Fairphone 101

    “Sustainable smartphone? How can a smartphone be sustainable?” Whenever we tell people about Fairphone, this is usually the standard response. And to be fair (pun intended), it is a valid question. Put bluntly, a smartphone that is 100% sustainable is not realistic, at least not right now. However, that doesn’t mean that smartphones (and by...

    En savoir plus
  • Our 2024 Impact Report is out. Here are the highlights.

    Our 2024 Impact Report is out. Here are the highlights.

    48% reduction in greenhouse gas emissions. 20,000+ people with fairer working conditions. 29 tons of e-waste collected. 69.5% fair and recycled material in our newest product. Our impact work is what makes Fairphone synonymous with sustainable tech. When people ask us what it means to make electronics sustainable, we have A LOT to say and...

    En savoir plus

Newsletter Fairphone

Vous voulez rester au courant de tout ce qui concerne Fairphone ?

Inscrivez-vous à notre newsletter pour obtenir des mises à jour régulières sur Fairphone

Inscrivez-vous à notre newsletter et recevez 5€ de remise sur votre prochaine commande

Votre réduction de 5€ sera envoyée à l’adresse e-mail que vous avez fournie. Le coupon peut être utilisé sur votre prochaine commande de plus de 75 €. S’il vous plaît être conscient que notre principale langue de communication est l’anglais. En vous abonnant, vous acceptez nos conditions d’utilisation et notre Politique de confidentialité et d’utilisation des cookies. Nous vous demandons votre nom et votre adresse e-mail pour que vous puissiez recevoir notre lettre d’information sur les projets Fairphone et les mises à jour de ses produits. Vous pouvez supprimer ou modifier l’autorisation à tout moment.

Close