Simple Cyber Defense

Security flaw in Moto G5 Plus Prime Exclusive grants access to phone with the tap of a lockscreen ad


Amazon has been running its Prime Exclusive program for some time now. Essentially, the company partners with phone manufacturers to offer noticeably lower prices on devices in exchange for preloaded Amazon apps and advertisements on the lock screen. However, it appears that these lockscreen ads have led to a security flaw on one Prime Exclusive device, the Moto G5 Plus.

Reports are that anyone can gain access to your phone just by tapping on the lockscreen ad. Further review of the issues shows that it is a result of having Smart Lock’s on-body detection feature enabled.

Hey @amazon @MotorolaUS. I found a security flaw in my Amazon motot g5. Hit fingerprint sensor (it says fingerprint not recognized), then press power button, then click view ad on the lockscreen. This gives you 100% access to the phone.

— Jaraszski Colliefox (@jaraszski) January 22, 2018

Source: Android Police