Android Hacked via NFC on the Samsung Galaxy S3
thenextweb.com
thenextweb.com
Why not? Ever since I heard of the idea of trying to replace QR codes with passive always on NFC I've thought that this will be one of the first methods for massive infections of smartphones. Just put one in a public place(public transportation, store, etc.)
Note you only have to slam a shim in; the shim can then download an arbitrary payload.
[1]: http://krebsonsecurity.com/2012/07/atm-skimmers-get-wafer-th...
The only unique theoretical option would be to hack a very highpowered antenna and transmitter to try and pick up blast out RFID-compatible signals to/from the very weak NFC radios of handsets from further away.
And attacks doesn't need to come from cots phones, with your own higher gain NFC device, you can interact with with ordinary NFC devices from greater distances.
http://www.nfcworld.com/2012/08/01/317100/forum-responds-to-...
How long would that take to trigger through the NFC interface?
The use of NFC for the demo was showmanship, basically. It gets them attention, and also serves to point out that a comparatively-little-known feature of the phone can be an attack vector too.
- Android 4.1+ (JB and above) include full ASLR which will mitigate this vulnerability somewhat
- From my own Android experience, the screen must be active for the NFC receiver to active. This means the phone can't be exploited while it sits in your pocket.